diff --git a/advisories/unreviewed/2022/03/GHSA-hm3x-qqp4-vg9x/GHSA-hm3x-qqp4-vg9x.json b/advisories/unreviewed/2022/03/GHSA-hm3x-qqp4-vg9x/GHSA-hm3x-qqp4-vg9x.json
index 7778d16cbd8..f756369a391 100644
--- a/advisories/unreviewed/2022/03/GHSA-hm3x-qqp4-vg9x/GHSA-hm3x-qqp4-vg9x.json
+++ b/advisories/unreviewed/2022/03/GHSA-hm3x-qqp4-vg9x/GHSA-hm3x-qqp4-vg9x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hm3x-qqp4-vg9x",
- "modified": "2022-03-22T00:00:59Z",
+ "modified": "2025-05-07T15:31:13Z",
"published": "2022-03-12T00:00:27Z",
"aliases": [
"CVE-2022-25600"
@@ -19,6 +19,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25600"
},
+ {
+ "type": "WEB",
+ "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7CR6VGITIB2TXXZ6B5QRRWPU5S4BXQPD"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJX6NVXSRN3RX3YUVEJQ4WUTQSDL3DSR"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZQCIZQI267YHVYSFB3CRKNK3F4ASPLK"
+ },
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7CR6VGITIB2TXXZ6B5QRRWPU5S4BXQPD"
diff --git a/advisories/unreviewed/2022/05/GHSA-3xhc-3pqp-v39v/GHSA-3xhc-3pqp-v39v.json b/advisories/unreviewed/2022/05/GHSA-3xhc-3pqp-v39v/GHSA-3xhc-3pqp-v39v.json
index ff236b216ba..3629ecd8828 100644
--- a/advisories/unreviewed/2022/05/GHSA-3xhc-3pqp-v39v/GHSA-3xhc-3pqp-v39v.json
+++ b/advisories/unreviewed/2022/05/GHSA-3xhc-3pqp-v39v/GHSA-3xhc-3pqp-v39v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3xhc-3pqp-v39v",
- "modified": "2022-05-24T17:44:49Z",
+ "modified": "2025-05-07T15:31:13Z",
"published": "2022-05-24T17:44:49Z",
"aliases": [
"CVE-2021-24130"
],
"details": "Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
diff --git a/advisories/unreviewed/2022/05/GHSA-7hcc-mq7f-h4mv/GHSA-7hcc-mq7f-h4mv.json b/advisories/unreviewed/2022/05/GHSA-7hcc-mq7f-h4mv/GHSA-7hcc-mq7f-h4mv.json
index 2890a5e064f..b49d9179a74 100644
--- a/advisories/unreviewed/2022/05/GHSA-7hcc-mq7f-h4mv/GHSA-7hcc-mq7f-h4mv.json
+++ b/advisories/unreviewed/2022/05/GHSA-7hcc-mq7f-h4mv/GHSA-7hcc-mq7f-h4mv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7hcc-mq7f-h4mv",
- "modified": "2022-05-24T19:10:28Z",
+ "modified": "2025-05-07T15:31:13Z",
"published": "2022-05-24T19:10:28Z",
"aliases": [
"CVE-2021-24502"
],
"details": "The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
diff --git a/advisories/unreviewed/2022/10/GHSA-2p5h-g3vp-7934/GHSA-2p5h-g3vp-7934.json b/advisories/unreviewed/2022/10/GHSA-2p5h-g3vp-7934/GHSA-2p5h-g3vp-7934.json
index c7f43054fc1..41a73c686f0 100644
--- a/advisories/unreviewed/2022/10/GHSA-2p5h-g3vp-7934/GHSA-2p5h-g3vp-7934.json
+++ b/advisories/unreviewed/2022/10/GHSA-2p5h-g3vp-7934/GHSA-2p5h-g3vp-7934.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p5h-g3vp-7934",
- "modified": "2022-10-29T12:00:48Z",
+ "modified": "2025-05-07T15:31:17Z",
"published": "2022-10-27T12:00:27Z",
"aliases": [
"CVE-2022-2508"
diff --git a/advisories/unreviewed/2022/10/GHSA-4cv7-c8cq-mg9f/GHSA-4cv7-c8cq-mg9f.json b/advisories/unreviewed/2022/10/GHSA-4cv7-c8cq-mg9f/GHSA-4cv7-c8cq-mg9f.json
index a376711060d..a210ad6c41d 100644
--- a/advisories/unreviewed/2022/10/GHSA-4cv7-c8cq-mg9f/GHSA-4cv7-c8cq-mg9f.json
+++ b/advisories/unreviewed/2022/10/GHSA-4cv7-c8cq-mg9f/GHSA-4cv7-c8cq-mg9f.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-22"
+ "CWE-22",
+ "CWE-78"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/10/GHSA-5fw4-hg92-mgm7/GHSA-5fw4-hg92-mgm7.json b/advisories/unreviewed/2022/10/GHSA-5fw4-hg92-mgm7/GHSA-5fw4-hg92-mgm7.json
index 201fcbeedca..3895ae6b9c1 100644
--- a/advisories/unreviewed/2022/10/GHSA-5fw4-hg92-mgm7/GHSA-5fw4-hg92-mgm7.json
+++ b/advisories/unreviewed/2022/10/GHSA-5fw4-hg92-mgm7/GHSA-5fw4-hg92-mgm7.json
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-532",
"CWE-668"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2022/10/GHSA-6468-68pw-9chw/GHSA-6468-68pw-9chw.json b/advisories/unreviewed/2022/10/GHSA-6468-68pw-9chw/GHSA-6468-68pw-9chw.json
index 1e1207179a5..4ccffcbc8ce 100644
--- a/advisories/unreviewed/2022/10/GHSA-6468-68pw-9chw/GHSA-6468-68pw-9chw.json
+++ b/advisories/unreviewed/2022/10/GHSA-6468-68pw-9chw/GHSA-6468-68pw-9chw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6468-68pw-9chw",
- "modified": "2022-10-24T19:00:18Z",
+ "modified": "2025-05-07T15:31:14Z",
"published": "2022-10-24T19:00:18Z",
"aliases": [
"CVE-2021-46848"
@@ -35,6 +35,22 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00003.html"
},
+ {
+ "type": "WEB",
+ "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AV4SHDJF2XLB4CUPTBPQQ6CLGZ5LKXPZ"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ECM2ELTVRYV4BZ5L5GMIRQE27RFHPAQ6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OGO7XST4EIJGX4B2ITZCYSWM24534BSU"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V5LWOGF7QRMNFRUCZY6TDYQJVFI6MOQ2"
+ },
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AV4SHDJF2XLB4CUPTBPQQ6CLGZ5LKXPZ"
@@ -58,7 +74,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-125"
+ "CWE-125",
+ "CWE-193"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/10/GHSA-6p9q-3fp4-ff53/GHSA-6p9q-3fp4-ff53.json b/advisories/unreviewed/2022/10/GHSA-6p9q-3fp4-ff53/GHSA-6p9q-3fp4-ff53.json
index 58fae3d504f..4fe06b4807a 100644
--- a/advisories/unreviewed/2022/10/GHSA-6p9q-3fp4-ff53/GHSA-6p9q-3fp4-ff53.json
+++ b/advisories/unreviewed/2022/10/GHSA-6p9q-3fp4-ff53/GHSA-6p9q-3fp4-ff53.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6p9q-3fp4-ff53",
- "modified": "2022-11-01T19:00:29Z",
+ "modified": "2025-05-07T15:31:19Z",
"published": "2022-10-31T19:00:36Z",
"aliases": [
"CVE-2020-21016"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-94"
+ ],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/10/GHSA-7v37-cpgh-grvq/GHSA-7v37-cpgh-grvq.json b/advisories/unreviewed/2022/10/GHSA-7v37-cpgh-grvq/GHSA-7v37-cpgh-grvq.json
index 2b968294f53..5da2c4820fa 100644
--- a/advisories/unreviewed/2022/10/GHSA-7v37-cpgh-grvq/GHSA-7v37-cpgh-grvq.json
+++ b/advisories/unreviewed/2022/10/GHSA-7v37-cpgh-grvq/GHSA-7v37-cpgh-grvq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7v37-cpgh-grvq",
- "modified": "2022-10-28T19:00:42Z",
+ "modified": "2025-05-07T15:31:16Z",
"published": "2022-10-27T12:00:35Z",
"aliases": [
"CVE-2022-42999"
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-77"
+ "CWE-77",
+ "CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/10/GHSA-84x9-g98v-6qpc/GHSA-84x9-g98v-6qpc.json b/advisories/unreviewed/2022/10/GHSA-84x9-g98v-6qpc/GHSA-84x9-g98v-6qpc.json
index 0bf081711ab..1751396737c 100644
--- a/advisories/unreviewed/2022/10/GHSA-84x9-g98v-6qpc/GHSA-84x9-g98v-6qpc.json
+++ b/advisories/unreviewed/2022/10/GHSA-84x9-g98v-6qpc/GHSA-84x9-g98v-6qpc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84x9-g98v-6qpc",
- "modified": "2022-10-28T19:00:42Z",
+ "modified": "2025-05-07T15:31:16Z",
"published": "2022-10-27T12:00:35Z",
"aliases": [
"CVE-2022-43002"
diff --git a/advisories/unreviewed/2022/10/GHSA-88q3-c9m5-9945/GHSA-88q3-c9m5-9945.json b/advisories/unreviewed/2022/10/GHSA-88q3-c9m5-9945/GHSA-88q3-c9m5-9945.json
index 3028877a75c..054b9ae4b97 100644
--- a/advisories/unreviewed/2022/10/GHSA-88q3-c9m5-9945/GHSA-88q3-c9m5-9945.json
+++ b/advisories/unreviewed/2022/10/GHSA-88q3-c9m5-9945/GHSA-88q3-c9m5-9945.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88q3-c9m5-9945",
- "modified": "2022-10-28T19:00:42Z",
+ "modified": "2025-05-07T15:31:15Z",
"published": "2022-10-26T12:00:31Z",
"aliases": [
"CVE-2022-33184"
diff --git a/advisories/unreviewed/2022/10/GHSA-8g74-45pc-67v3/GHSA-8g74-45pc-67v3.json b/advisories/unreviewed/2022/10/GHSA-8g74-45pc-67v3/GHSA-8g74-45pc-67v3.json
index adebe69a920..32d19508eec 100644
--- a/advisories/unreviewed/2022/10/GHSA-8g74-45pc-67v3/GHSA-8g74-45pc-67v3.json
+++ b/advisories/unreviewed/2022/10/GHSA-8g74-45pc-67v3/GHSA-8g74-45pc-67v3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8g74-45pc-67v3",
- "modified": "2022-10-28T19:00:42Z",
+ "modified": "2025-05-07T15:31:16Z",
"published": "2022-10-27T12:00:35Z",
"aliases": [
"CVE-2022-43000"
diff --git a/advisories/unreviewed/2022/10/GHSA-9gvf-7m63-wqh9/GHSA-9gvf-7m63-wqh9.json b/advisories/unreviewed/2022/10/GHSA-9gvf-7m63-wqh9/GHSA-9gvf-7m63-wqh9.json
index 7f64943acd9..5919d0563d3 100644
--- a/advisories/unreviewed/2022/10/GHSA-9gvf-7m63-wqh9/GHSA-9gvf-7m63-wqh9.json
+++ b/advisories/unreviewed/2022/10/GHSA-9gvf-7m63-wqh9/GHSA-9gvf-7m63-wqh9.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-269"
+ "CWE-269",
+ "CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/10/GHSA-f4hw-g4gh-mmch/GHSA-f4hw-g4gh-mmch.json b/advisories/unreviewed/2022/10/GHSA-f4hw-g4gh-mmch/GHSA-f4hw-g4gh-mmch.json
index dde76c81e10..16839bbad50 100644
--- a/advisories/unreviewed/2022/10/GHSA-f4hw-g4gh-mmch/GHSA-f4hw-g4gh-mmch.json
+++ b/advisories/unreviewed/2022/10/GHSA-f4hw-g4gh-mmch/GHSA-f4hw-g4gh-mmch.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-78"
+ ],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/10/GHSA-ffhx-6p84-463h/GHSA-ffhx-6p84-463h.json b/advisories/unreviewed/2022/10/GHSA-ffhx-6p84-463h/GHSA-ffhx-6p84-463h.json
index 62223f75824..fb45c51fad1 100644
--- a/advisories/unreviewed/2022/10/GHSA-ffhx-6p84-463h/GHSA-ffhx-6p84-463h.json
+++ b/advisories/unreviewed/2022/10/GHSA-ffhx-6p84-463h/GHSA-ffhx-6p84-463h.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-77"
+ "CWE-77",
+ "CWE-88"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/10/GHSA-fgh9-wfj4-j5gv/GHSA-fgh9-wfj4-j5gv.json b/advisories/unreviewed/2022/10/GHSA-fgh9-wfj4-j5gv/GHSA-fgh9-wfj4-j5gv.json
index 8289f662d2c..da435d3ecf4 100644
--- a/advisories/unreviewed/2022/10/GHSA-fgh9-wfj4-j5gv/GHSA-fgh9-wfj4-j5gv.json
+++ b/advisories/unreviewed/2022/10/GHSA-fgh9-wfj4-j5gv/GHSA-fgh9-wfj4-j5gv.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-787"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2022/10/GHSA-fxr6-45h7-wgcx/GHSA-fxr6-45h7-wgcx.json b/advisories/unreviewed/2022/10/GHSA-fxr6-45h7-wgcx/GHSA-fxr6-45h7-wgcx.json
index 586fc92ca96..7ee51da88bf 100644
--- a/advisories/unreviewed/2022/10/GHSA-fxr6-45h7-wgcx/GHSA-fxr6-45h7-wgcx.json
+++ b/advisories/unreviewed/2022/10/GHSA-fxr6-45h7-wgcx/GHSA-fxr6-45h7-wgcx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fxr6-45h7-wgcx",
- "modified": "2022-10-24T19:00:20Z",
+ "modified": "2025-05-07T15:31:13Z",
"published": "2022-10-24T19:00:20Z",
"aliases": [
"CVE-2022-40690"
diff --git a/advisories/unreviewed/2022/10/GHSA-g8h6-gmhw-mc7m/GHSA-g8h6-gmhw-mc7m.json b/advisories/unreviewed/2022/10/GHSA-g8h6-gmhw-mc7m/GHSA-g8h6-gmhw-mc7m.json
index a17d6840731..38ee0ba3aad 100644
--- a/advisories/unreviewed/2022/10/GHSA-g8h6-gmhw-mc7m/GHSA-g8h6-gmhw-mc7m.json
+++ b/advisories/unreviewed/2022/10/GHSA-g8h6-gmhw-mc7m/GHSA-g8h6-gmhw-mc7m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g8h6-gmhw-mc7m",
- "modified": "2023-01-21T03:30:28Z",
+ "modified": "2025-05-07T15:31:13Z",
"published": "2022-10-21T19:01:14Z",
"aliases": [
"CVE-2022-3627"
diff --git a/advisories/unreviewed/2022/10/GHSA-j4j6-6hfx-pfq5/GHSA-j4j6-6hfx-pfq5.json b/advisories/unreviewed/2022/10/GHSA-j4j6-6hfx-pfq5/GHSA-j4j6-6hfx-pfq5.json
index 41dfa8fcf23..055ac08fc99 100644
--- a/advisories/unreviewed/2022/10/GHSA-j4j6-6hfx-pfq5/GHSA-j4j6-6hfx-pfq5.json
+++ b/advisories/unreviewed/2022/10/GHSA-j4j6-6hfx-pfq5/GHSA-j4j6-6hfx-pfq5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j4j6-6hfx-pfq5",
- "modified": "2022-10-28T19:00:42Z",
+ "modified": "2025-05-07T15:31:16Z",
"published": "2022-10-27T12:00:35Z",
"aliases": [
"CVE-2022-42998"
diff --git a/advisories/unreviewed/2022/10/GHSA-m634-qv6v-fgvh/GHSA-m634-qv6v-fgvh.json b/advisories/unreviewed/2022/10/GHSA-m634-qv6v-fgvh/GHSA-m634-qv6v-fgvh.json
index 628b5914c94..8667c2eae3a 100644
--- a/advisories/unreviewed/2022/10/GHSA-m634-qv6v-fgvh/GHSA-m634-qv6v-fgvh.json
+++ b/advisories/unreviewed/2022/10/GHSA-m634-qv6v-fgvh/GHSA-m634-qv6v-fgvh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m634-qv6v-fgvh",
- "modified": "2022-10-28T19:00:42Z",
+ "modified": "2025-05-07T15:31:16Z",
"published": "2022-10-27T12:00:35Z",
"aliases": [
"CVE-2022-43001"
diff --git a/advisories/unreviewed/2022/10/GHSA-w897-xc8j-4g89/GHSA-w897-xc8j-4g89.json b/advisories/unreviewed/2022/10/GHSA-w897-xc8j-4g89/GHSA-w897-xc8j-4g89.json
index e6b740f1138..ae4be373f71 100644
--- a/advisories/unreviewed/2022/10/GHSA-w897-xc8j-4g89/GHSA-w897-xc8j-4g89.json
+++ b/advisories/unreviewed/2022/10/GHSA-w897-xc8j-4g89/GHSA-w897-xc8j-4g89.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w897-xc8j-4g89",
- "modified": "2022-10-28T19:00:41Z",
+ "modified": "2025-05-07T15:31:17Z",
"published": "2022-10-27T12:00:35Z",
"aliases": [
"CVE-2022-43003"
diff --git a/advisories/unreviewed/2022/10/GHSA-xmj6-5q7j-j6gg/GHSA-xmj6-5q7j-j6gg.json b/advisories/unreviewed/2022/10/GHSA-xmj6-5q7j-j6gg/GHSA-xmj6-5q7j-j6gg.json
index ed6dd819fac..5233a2c1948 100644
--- a/advisories/unreviewed/2022/10/GHSA-xmj6-5q7j-j6gg/GHSA-xmj6-5q7j-j6gg.json
+++ b/advisories/unreviewed/2022/10/GHSA-xmj6-5q7j-j6gg/GHSA-xmj6-5q7j-j6gg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xmj6-5q7j-j6gg",
- "modified": "2022-10-29T12:00:50Z",
+ "modified": "2025-05-07T15:31:14Z",
"published": "2022-10-25T19:00:29Z",
"aliases": [
"CVE-2022-3344"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2130278"
},
+ {
+ "type": "WEB",
+ "url": "https://lore.kernel.org/lkml/20221020093055.224317-5-mlevitsk%40redhat.com/T"
+ },
{
"type": "WEB",
"url": "https://lore.kernel.org/lkml/20221020093055.224317-5-mlevitsk@redhat.com/T"
diff --git a/advisories/unreviewed/2023/07/GHSA-52r6-x37j-435c/GHSA-52r6-x37j-435c.json b/advisories/unreviewed/2023/07/GHSA-52r6-x37j-435c/GHSA-52r6-x37j-435c.json
index 704e1de718d..bf9dfb98545 100644
--- a/advisories/unreviewed/2023/07/GHSA-52r6-x37j-435c/GHSA-52r6-x37j-435c.json
+++ b/advisories/unreviewed/2023/07/GHSA-52r6-x37j-435c/GHSA-52r6-x37j-435c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52r6-x37j-435c",
- "modified": "2024-04-04T05:29:57Z",
+ "modified": "2025-05-07T15:31:14Z",
"published": "2023-07-06T19:24:03Z",
"aliases": [
"CVE-2022-33183"
diff --git a/advisories/unreviewed/2023/07/GHSA-mj6f-85xq-rjq8/GHSA-mj6f-85xq-rjq8.json b/advisories/unreviewed/2023/07/GHSA-mj6f-85xq-rjq8/GHSA-mj6f-85xq-rjq8.json
index ddc8c47f623..fba2e5b5b28 100644
--- a/advisories/unreviewed/2023/07/GHSA-mj6f-85xq-rjq8/GHSA-mj6f-85xq-rjq8.json
+++ b/advisories/unreviewed/2023/07/GHSA-mj6f-85xq-rjq8/GHSA-mj6f-85xq-rjq8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mj6f-85xq-rjq8",
- "modified": "2024-04-04T05:29:55Z",
+ "modified": "2025-05-07T15:31:14Z",
"published": "2023-07-06T19:24:03Z",
"aliases": [
"CVE-2022-33182"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-276"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-mg3q-349p-vcpv/GHSA-mg3q-349p-vcpv.json b/advisories/unreviewed/2024/04/GHSA-mg3q-349p-vcpv/GHSA-mg3q-349p-vcpv.json
index b6a33eea023..a4d5b40ee36 100644
--- a/advisories/unreviewed/2024/04/GHSA-mg3q-349p-vcpv/GHSA-mg3q-349p-vcpv.json
+++ b/advisories/unreviewed/2024/04/GHSA-mg3q-349p-vcpv/GHSA-mg3q-349p-vcpv.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-269"
+ "CWE-269",
+ "CWE-522"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/06/GHSA-w8wf-rhcx-wvhg/GHSA-w8wf-rhcx-wvhg.json b/advisories/unreviewed/2024/06/GHSA-w8wf-rhcx-wvhg/GHSA-w8wf-rhcx-wvhg.json
index 9627ee43704..eb337507258 100644
--- a/advisories/unreviewed/2024/06/GHSA-w8wf-rhcx-wvhg/GHSA-w8wf-rhcx-wvhg.json
+++ b/advisories/unreviewed/2024/06/GHSA-w8wf-rhcx-wvhg/GHSA-w8wf-rhcx-wvhg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w8wf-rhcx-wvhg",
- "modified": "2024-06-17T06:30:35Z",
+ "modified": "2025-05-07T15:31:20Z",
"published": "2024-06-17T06:30:35Z",
"aliases": [
"CVE-2024-6047"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6047"
},
+ {
+ "type": "WEB",
+ "url": "https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet"
+ },
{
"type": "WEB",
"url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html"
diff --git a/advisories/unreviewed/2024/11/GHSA-hq2j-jpv4-q865/GHSA-hq2j-jpv4-q865.json b/advisories/unreviewed/2024/11/GHSA-hq2j-jpv4-q865/GHSA-hq2j-jpv4-q865.json
index b51fbed803a..4e008a4e782 100644
--- a/advisories/unreviewed/2024/11/GHSA-hq2j-jpv4-q865/GHSA-hq2j-jpv4-q865.json
+++ b/advisories/unreviewed/2024/11/GHSA-hq2j-jpv4-q865/GHSA-hq2j-jpv4-q865.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hq2j-jpv4-q865",
- "modified": "2024-11-15T03:31:10Z",
+ "modified": "2025-05-07T15:31:21Z",
"published": "2024-11-15T03:31:10Z",
"aliases": [
"CVE-2024-11120"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11120"
},
+ {
+ "type": "WEB",
+ "url": "https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet"
+ },
{
"type": "WEB",
"url": "https://www.twcert.org.tw/en/cp-139-8237-26d7a-2.html"
diff --git a/advisories/unreviewed/2024/12/GHSA-6p32-cp49-w842/GHSA-6p32-cp49-w842.json b/advisories/unreviewed/2024/12/GHSA-6p32-cp49-w842/GHSA-6p32-cp49-w842.json
index e210d0cce34..9d6eae66625 100644
--- a/advisories/unreviewed/2024/12/GHSA-6p32-cp49-w842/GHSA-6p32-cp49-w842.json
+++ b/advisories/unreviewed/2024/12/GHSA-6p32-cp49-w842/GHSA-6p32-cp49-w842.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/12/GHSA-c2gq-fxg8-22f9/GHSA-c2gq-fxg8-22f9.json b/advisories/unreviewed/2024/12/GHSA-c2gq-fxg8-22f9/GHSA-c2gq-fxg8-22f9.json
index c600facad16..a4ee6f76802 100644
--- a/advisories/unreviewed/2024/12/GHSA-c2gq-fxg8-22f9/GHSA-c2gq-fxg8-22f9.json
+++ b/advisories/unreviewed/2024/12/GHSA-c2gq-fxg8-22f9/GHSA-c2gq-fxg8-22f9.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-122"
+ "CWE-122",
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-jx47-v2mx-xmc3/GHSA-jx47-v2mx-xmc3.json b/advisories/unreviewed/2024/12/GHSA-jx47-v2mx-xmc3/GHSA-jx47-v2mx-xmc3.json
index b42dd53d0ac..37135594892 100644
--- a/advisories/unreviewed/2024/12/GHSA-jx47-v2mx-xmc3/GHSA-jx47-v2mx-xmc3.json
+++ b/advisories/unreviewed/2024/12/GHSA-jx47-v2mx-xmc3/GHSA-jx47-v2mx-xmc3.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/12/GHSA-p9v3-8f7q-wffx/GHSA-p9v3-8f7q-wffx.json b/advisories/unreviewed/2024/12/GHSA-p9v3-8f7q-wffx/GHSA-p9v3-8f7q-wffx.json
index 2e63fd2633c..1804c05ba8c 100644
--- a/advisories/unreviewed/2024/12/GHSA-p9v3-8f7q-wffx/GHSA-p9v3-8f7q-wffx.json
+++ b/advisories/unreviewed/2024/12/GHSA-p9v3-8f7q-wffx/GHSA-p9v3-8f7q-wffx.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/12/GHSA-rw7h-3g54-j855/GHSA-rw7h-3g54-j855.json b/advisories/unreviewed/2024/12/GHSA-rw7h-3g54-j855/GHSA-rw7h-3g54-j855.json
index b23ee33749c..9f1053fb83c 100644
--- a/advisories/unreviewed/2024/12/GHSA-rw7h-3g54-j855/GHSA-rw7h-3g54-j855.json
+++ b/advisories/unreviewed/2024/12/GHSA-rw7h-3g54-j855/GHSA-rw7h-3g54-j855.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/12/GHSA-vqvq-ggf5-9h68/GHSA-vqvq-ggf5-9h68.json b/advisories/unreviewed/2024/12/GHSA-vqvq-ggf5-9h68/GHSA-vqvq-ggf5-9h68.json
index bf6b56e4ae5..798d3d4ad32 100644
--- a/advisories/unreviewed/2024/12/GHSA-vqvq-ggf5-9h68/GHSA-vqvq-ggf5-9h68.json
+++ b/advisories/unreviewed/2024/12/GHSA-vqvq-ggf5-9h68/GHSA-vqvq-ggf5-9h68.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2025/05/GHSA-222r-jmhg-vqvf/GHSA-222r-jmhg-vqvf.json b/advisories/unreviewed/2025/05/GHSA-222r-jmhg-vqvf/GHSA-222r-jmhg-vqvf.json
new file mode 100644
index 00000000000..d74049a4c29
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-222r-jmhg-vqvf/GHSA-222r-jmhg-vqvf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-222r-jmhg-vqvf",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47620"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network allows Reflected XSS. This issue affects Martins Free Monetized Ad Exchange Network: from n/a through 1.0.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47620"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/martins-free-and-easy-ad-network-get-more-visitors/vulnerability/wordpress-martins-free-monetized-ad-exchange-network-plugin-1-0-5-csrf-to-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-24q5-v927-9w6j/GHSA-24q5-v927-9w6j.json b/advisories/unreviewed/2025/05/GHSA-24q5-v927-9w6j/GHSA-24q5-v927-9w6j.json
new file mode 100644
index 00000000000..6f42697b984
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-24q5-v927-9w6j/GHSA-24q5-v927-9w6j.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-24q5-v927-9w6j",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:42Z",
+ "aliases": [
+ "CVE-2025-47450"
+ ],
+ "details": "Missing Authorization vulnerability in Mitchell Bennis Simple File List allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple File List: from n/a through 6.1.13.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47450"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/simple-file-list/vulnerability/wordpress-simple-file-list-6-1-13-settings-change-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:59Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-262g-44pp-38c2/GHSA-262g-44pp-38c2.json b/advisories/unreviewed/2025/05/GHSA-262g-44pp-38c2/GHSA-262g-44pp-38c2.json
index 7e7364f9af7..21955dcd93d 100644
--- a/advisories/unreviewed/2025/05/GHSA-262g-44pp-38c2/GHSA-262g-44pp-38c2.json
+++ b/advisories/unreviewed/2025/05/GHSA-262g-44pp-38c2/GHSA-262g-44pp-38c2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-262g-44pp-38c2",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:28Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49926"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: Fix possible memory leaks in dsa_loop_init()\n\nkmemleak reported memory leaks in dsa_loop_init():\n\nkmemleak: 12 new suspected memory leaks\n\nunreferenced object 0xffff8880138ce000 (size 2048):\n comm \"modprobe\", pid 390, jiffies 4295040478 (age 238.976s)\n backtrace:\n [<000000006a94f1d5>] kmalloc_trace+0x26/0x60\n [<00000000a9c44622>] phy_device_create+0x5d/0x970\n [<00000000d0ee2afc>] get_phy_device+0xf3/0x2b0\n [<00000000dca0c71f>] __fixed_phy_register.part.0+0x92/0x4e0\n [<000000008a834798>] fixed_phy_register+0x84/0xb0\n [<0000000055223fcb>] dsa_loop_init+0xa9/0x116 [dsa_loop]\n ...\n\nThere are two reasons for memleak in dsa_loop_init().\n\nFirst, fixed_phy_register() create and register phy_device:\n\nfixed_phy_register()\n get_phy_device()\n phy_device_create() # freed by phy_device_free()\n phy_device_register() # freed by phy_device_remove()\n\nBut fixed_phy_unregister() only calls phy_device_remove().\nSo the memory allocated in phy_device_create() is leaked.\n\nSecond, when mdio_driver_register() fail in dsa_loop_init(),\nit just returns and there is no cleanup for phydevs.\n\nFix the problems by catching the error of mdio_driver_register()\nin dsa_loop_init(), then calling both fixed_phy_unregister() and\nphy_device_free() to release phydevs.\nAlso add a function for phydevs cleanup to avoid duplacate.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:18Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-28rp-5v4x-48wq/GHSA-28rp-5v4x-48wq.json b/advisories/unreviewed/2025/05/GHSA-28rp-5v4x-48wq/GHSA-28rp-5v4x-48wq.json
new file mode 100644
index 00000000000..3092b0cb87d
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-28rp-5v4x-48wq/GHSA-28rp-5v4x-48wq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-28rp-5v4x-48wq",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:42Z",
+ "aliases": [
+ "CVE-2025-47442"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CC CC BMI Calculator allows Stored XSS. This issue affects CC BMI Calculator: from n/a through 2.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47442"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/cc-bmi-calculator/vulnerability/wordpress-cc-bmi-calculator-2-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:58Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-2crp-r6g2-9c5p/GHSA-2crp-r6g2-9c5p.json b/advisories/unreviewed/2025/05/GHSA-2crp-r6g2-9c5p/GHSA-2crp-r6g2-9c5p.json
index a7ad2399b8e..cc7d4ee8110 100644
--- a/advisories/unreviewed/2025/05/GHSA-2crp-r6g2-9c5p/GHSA-2crp-r6g2-9c5p.json
+++ b/advisories/unreviewed/2025/05/GHSA-2crp-r6g2-9c5p/GHSA-2crp-r6g2-9c5p.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2crp-r6g2-9c5p",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49867"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: iosm: fix memory leak in ipc_wwan_dellink\n\nIOSM driver registers network device without setting the\nneeds_free_netdev flag, and does NOT call free_netdev() when\nunregisters network device, which causes a memory leak.\n\nThis patch sets needs_free_netdev to true when registers\nnetwork device, which makes netdev subsystem call free_netdev()\nautomatically after unregister_netdevice().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:11Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-2f39-5mgp-fmmr/GHSA-2f39-5mgp-fmmr.json b/advisories/unreviewed/2025/05/GHSA-2f39-5mgp-fmmr/GHSA-2f39-5mgp-fmmr.json
new file mode 100644
index 00000000000..c06de99ed01
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-2f39-5mgp-fmmr/GHSA-2f39-5mgp-fmmr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2f39-5mgp-fmmr",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47628"
+ ],
+ "details": "Missing Authorization vulnerability in quomodosoft QS Dark Mode allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QS Dark Mode: from n/a through 3.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47628"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/qs-dark-mode/vulnerability/wordpress-qs-dark-mode-3-0-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-2f6p-9573-fp98/GHSA-2f6p-9573-fp98.json b/advisories/unreviewed/2025/05/GHSA-2f6p-9573-fp98/GHSA-2f6p-9573-fp98.json
index 350c6881557..af1856cee6c 100644
--- a/advisories/unreviewed/2025/05/GHSA-2f6p-9573-fp98/GHSA-2f6p-9573-fp98.json
+++ b/advisories/unreviewed/2025/05/GHSA-2f6p-9573-fp98/GHSA-2f6p-9573-fp98.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2f6p-9573-fp98",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:52Z",
"aliases": [
"CVE-2022-49909"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix use-after-free in l2cap_conn_del()\n\nWhen l2cap_recv_frame() is invoked to receive data, and the cid is\nL2CAP_CID_A2MP, if the channel does not exist, it will create a channel.\nHowever, after a channel is created, the hold operation of the channel\nis not performed. In this case, the value of channel reference counting\nis 1. As a result, after hci_error_reset() is triggered, l2cap_conn_del()\ninvokes the close hook function of A2MP to release the channel. Then\n l2cap_chan_unlock(chan) will trigger UAF issue.\n\nThe process is as follows:\nReceive data:\nl2cap_data_channel()\n a2mp_channel_create() --->channel ref is 2\n l2cap_chan_put() --->channel ref is 1\n\nTriger event:\n hci_error_reset()\n hci_dev_do_close()\n ...\n l2cap_disconn_cfm()\n l2cap_conn_del()\n l2cap_chan_hold() --->channel ref is 2\n l2cap_chan_del() --->channel ref is 1\n a2mp_chan_close_cb() --->channel ref is 0, release channel\n l2cap_chan_unlock() --->UAF of channel\n\nThe detailed Call Trace is as follows:\nBUG: KASAN: use-after-free in __mutex_unlock_slowpath+0xa6/0x5e0\nRead of size 8 at addr ffff8880160664b8 by task kworker/u11:1/7593\nWorkqueue: hci0 hci_error_reset\nCall Trace:\n \n dump_stack_lvl+0xcd/0x134\n print_report.cold+0x2ba/0x719\n kasan_report+0xb1/0x1e0\n kasan_check_range+0x140/0x190\n __mutex_unlock_slowpath+0xa6/0x5e0\n l2cap_conn_del+0x404/0x7b0\n l2cap_disconn_cfm+0x8c/0xc0\n hci_conn_hash_flush+0x11f/0x260\n hci_dev_close_sync+0x5f5/0x11f0\n hci_dev_do_close+0x2d/0x70\n hci_error_reset+0x9e/0x140\n process_one_work+0x98a/0x1620\n worker_thread+0x665/0x1080\n kthread+0x2e4/0x3a0\n ret_from_fork+0x1f/0x30\n \n\nAllocated by task 7593:\n kasan_save_stack+0x1e/0x40\n __kasan_kmalloc+0xa9/0xd0\n l2cap_chan_create+0x40/0x930\n amp_mgr_create+0x96/0x990\n a2mp_channel_create+0x7d/0x150\n l2cap_recv_frame+0x51b8/0x9a70\n l2cap_recv_acldata+0xaa3/0xc00\n hci_rx_work+0x702/0x1220\n process_one_work+0x98a/0x1620\n worker_thread+0x665/0x1080\n kthread+0x2e4/0x3a0\n ret_from_fork+0x1f/0x30\n\nFreed by task 7593:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_set_free_info+0x20/0x30\n ____kasan_slab_free+0x167/0x1c0\n slab_free_freelist_hook+0x89/0x1c0\n kfree+0xe2/0x580\n l2cap_chan_put+0x22a/0x2d0\n l2cap_conn_del+0x3fc/0x7b0\n l2cap_disconn_cfm+0x8c/0xc0\n hci_conn_hash_flush+0x11f/0x260\n hci_dev_close_sync+0x5f5/0x11f0\n hci_dev_do_close+0x2d/0x70\n hci_error_reset+0x9e/0x140\n process_one_work+0x98a/0x1620\n worker_thread+0x665/0x1080\n kthread+0x2e4/0x3a0\n ret_from_fork+0x1f/0x30\n\nLast potentially related work creation:\n kasan_save_stack+0x1e/0x40\n __kasan_record_aux_stack+0xbe/0xd0\n call_rcu+0x99/0x740\n netlink_release+0xe6a/0x1cf0\n __sock_release+0xcd/0x280\n sock_close+0x18/0x20\n __fput+0x27c/0xa90\n task_work_run+0xdd/0x1a0\n exit_to_user_mode_prepare+0x23c/0x250\n syscall_exit_to_user_mode+0x19/0x50\n do_syscall_64+0x42/0x80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nSecond to last potentially related work creation:\n kasan_save_stack+0x1e/0x40\n __kasan_record_aux_stack+0xbe/0xd0\n call_rcu+0x99/0x740\n netlink_release+0xe6a/0x1cf0\n __sock_release+0xcd/0x280\n sock_close+0x18/0x20\n __fput+0x27c/0xa90\n task_work_run+0xdd/0x1a0\n exit_to_user_mode_prepare+0x23c/0x250\n syscall_exit_to_user_mode+0x19/0x50\n do_syscall_64+0x42/0x80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:16Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-2hxc-85rf-9fw9/GHSA-2hxc-85rf-9fw9.json b/advisories/unreviewed/2025/05/GHSA-2hxc-85rf-9fw9/GHSA-2hxc-85rf-9fw9.json
new file mode 100644
index 00000000000..54df562fc93
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-2hxc-85rf-9fw9/GHSA-2hxc-85rf-9fw9.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2hxc-85rf-9fw9",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47546"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress allows Cross Site Request Forgery. This issue affects WP Compress: from n/a through 6.30.30.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47546"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-compress-image-optimizer/vulnerability/wordpress-wp-compress-6-30-30-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-2j4h-4639-xjfj/GHSA-2j4h-4639-xjfj.json b/advisories/unreviewed/2025/05/GHSA-2j4h-4639-xjfj/GHSA-2j4h-4639-xjfj.json
new file mode 100644
index 00000000000..ad89fcb15a7
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-2j4h-4639-xjfj/GHSA-2j4h-4639-xjfj.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2j4h-4639-xjfj",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:42Z",
+ "aliases": [
+ "CVE-2025-47448"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47448"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-hotel-booking/vulnerability/wordpress-wp-hotel-booking-2-1-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:58Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-2mwj-p2rg-6r6v/GHSA-2mwj-p2rg-6r6v.json b/advisories/unreviewed/2025/05/GHSA-2mwj-p2rg-6r6v/GHSA-2mwj-p2rg-6r6v.json
new file mode 100644
index 00000000000..72d52d59ef7
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-2mwj-p2rg-6r6v/GHSA-2mwj-p2rg-6r6v.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2mwj-p2rg-6r6v",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47537"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF Invoices for WooCommerce + Drag and Drop Template Builder allows SQL Injection. This issue affects PDF Invoices for WooCommerce + Drag and Drop Template Builder: from n/a through 5.3.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47537"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/pdf-for-woocommerce/vulnerability/wordpress-pdf-invoices-for-woocommerce-drag-and-drop-template-builder-5-3-8-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-2rm8-gh6q-8wpp/GHSA-2rm8-gh6q-8wpp.json b/advisories/unreviewed/2025/05/GHSA-2rm8-gh6q-8wpp/GHSA-2rm8-gh6q-8wpp.json
new file mode 100644
index 00000000000..63a916caf98
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-2rm8-gh6q-8wpp/GHSA-2rm8-gh6q-8wpp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2rm8-gh6q-8wpp",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47473"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit allows Cross Site Request Forgery. This issue affects PW WooCommerce Bulk Edit: from n/a through 2.134.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47473"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/pw-bulk-edit/vulnerability/wordpress-pw-woocommerce-bulk-edit-2-134-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-32c5-q8cj-xx83/GHSA-32c5-q8cj-xx83.json b/advisories/unreviewed/2025/05/GHSA-32c5-q8cj-xx83/GHSA-32c5-q8cj-xx83.json
index 5c1f640deae..0ef8c7dac01 100644
--- a/advisories/unreviewed/2025/05/GHSA-32c5-q8cj-xx83/GHSA-32c5-q8cj-xx83.json
+++ b/advisories/unreviewed/2025/05/GHSA-32c5-q8cj-xx83/GHSA-32c5-q8cj-xx83.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32c5-q8cj-xx83",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49866"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: mhi: fix memory leak in mhi_mbim_dellink\n\nMHI driver registers network device without setting the\nneeds_free_netdev flag, and does NOT call free_netdev() when\nunregisters network device, which causes a memory leak.\n\nThis patch sets needs_free_netdev to true when registers\nnetwork device, which makes netdev subsystem call free_netdev()\nautomatically after unregister_netdevice().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:11Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-32r9-qhg6-prph/GHSA-32r9-qhg6-prph.json b/advisories/unreviewed/2025/05/GHSA-32r9-qhg6-prph/GHSA-32r9-qhg6-prph.json
new file mode 100644
index 00000000000..70fc3681fc2
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-32r9-qhg6-prph/GHSA-32r9-qhg6-prph.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-32r9-qhg6-prph",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47643"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce allows SQL Injection. This issue affects ELEX Product Feed for WooCommerce: from n/a through 3.1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47643"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/elex-product-feed/vulnerability/wordpress-elex-product-feed-for-woocommerce-3-1-2-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-33xq-rr72-hjfj/GHSA-33xq-rr72-hjfj.json b/advisories/unreviewed/2025/05/GHSA-33xq-rr72-hjfj/GHSA-33xq-rr72-hjfj.json
index a7cef53a114..852b8753671 100644
--- a/advisories/unreviewed/2025/05/GHSA-33xq-rr72-hjfj/GHSA-33xq-rr72-hjfj.json
+++ b/advisories/unreviewed/2025/05/GHSA-33xq-rr72-hjfj/GHSA-33xq-rr72-hjfj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33xq-rr72-hjfj",
- "modified": "2025-05-06T18:30:38Z",
+ "modified": "2025-05-07T15:31:36Z",
"published": "2025-05-06T18:30:38Z",
"aliases": [
"CVE-2025-45491"
],
"details": "Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-78"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-06T16:15:31Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-34jg-44wj-8r3p/GHSA-34jg-44wj-8r3p.json b/advisories/unreviewed/2025/05/GHSA-34jg-44wj-8r3p/GHSA-34jg-44wj-8r3p.json
index 24a628b7a9a..fb2cc3b4078 100644
--- a/advisories/unreviewed/2025/05/GHSA-34jg-44wj-8r3p/GHSA-34jg-44wj-8r3p.json
+++ b/advisories/unreviewed/2025/05/GHSA-34jg-44wj-8r3p/GHSA-34jg-44wj-8r3p.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34jg-44wj-8r3p",
- "modified": "2025-05-06T21:30:49Z",
+ "modified": "2025-05-07T15:31:36Z",
"published": "2025-05-06T21:30:49Z",
"aliases": [
"CVE-2025-44073"
],
"details": "SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-06T21:16:19Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-37jg-g7cq-cj49/GHSA-37jg-g7cq-cj49.json b/advisories/unreviewed/2025/05/GHSA-37jg-g7cq-cj49/GHSA-37jg-g7cq-cj49.json
new file mode 100644
index 00000000000..5dee9b740f5
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-37jg-g7cq-cj49/GHSA-37jg-g7cq-cj49.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-37jg-g7cq-cj49",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47669"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sabuj Kundu CBX Map for Google Map & OpenStreetMap allows DOM-Based XSS. This issue affects CBX Map for Google Map & OpenStreetMap: from n/a through 1.1.12.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47669"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/cbxgooglemap/vulnerability/wordpress-cbx-map-for-google-map-openstreetmap-1-1-12-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-37mw-ccj4-5q2g/GHSA-37mw-ccj4-5q2g.json b/advisories/unreviewed/2025/05/GHSA-37mw-ccj4-5q2g/GHSA-37mw-ccj4-5q2g.json
new file mode 100644
index 00000000000..ebf962213c1
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-37mw-ccj4-5q2g/GHSA-37mw-ccj4-5q2g.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-37mw-ccj4-5q2g",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47622"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in apasionados Email Notification on Login allows Stored XSS. This issue affects Email Notification on Login: from n/a through 1.6.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47622"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/email-notification-on-login/vulnerability/wordpress-email-notification-on-login-1-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-3g7w-h796-wcg5/GHSA-3g7w-h796-wcg5.json b/advisories/unreviewed/2025/05/GHSA-3g7w-h796-wcg5/GHSA-3g7w-h796-wcg5.json
index 14aef784598..3e1356e46b4 100644
--- a/advisories/unreviewed/2025/05/GHSA-3g7w-h796-wcg5/GHSA-3g7w-h796-wcg5.json
+++ b/advisories/unreviewed/2025/05/GHSA-3g7w-h796-wcg5/GHSA-3g7w-h796-wcg5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g7w-h796-wcg5",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49896"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/pmem: Fix cxl_pmem_region and cxl_memdev leak\n\nWhen a cxl_nvdimm object goes through a ->remove() event (device\nphysically removed, nvdimm-bridge disabled, or nvdimm device disabled),\nthen any associated regions must also be disabled. As highlighted by the\ncxl-create-region.sh test [1], a single device may host multiple\nregions, but the driver was only tracking one region at a time. This\nleads to a situation where only the last enabled region per nvdimm\ndevice is cleaned up properly. Other regions are leaked, and this also\ncauses cxl_memdev reference leaks.\n\nFix the tracking by allowing cxl_nvdimm objects to track multiple region\nassociations.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:14Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-3mh8-97g4-p2mv/GHSA-3mh8-97g4-p2mv.json b/advisories/unreviewed/2025/05/GHSA-3mh8-97g4-p2mv/GHSA-3mh8-97g4-p2mv.json
index efc22e761ca..b5d3fbfb45a 100644
--- a/advisories/unreviewed/2025/05/GHSA-3mh8-97g4-p2mv/GHSA-3mh8-97g4-p2mv.json
+++ b/advisories/unreviewed/2025/05/GHSA-3mh8-97g4-p2mv/GHSA-3mh8-97g4-p2mv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mh8-97g4-p2mv",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:27Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49919"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: release flow rule object from commit path\n\nNo need to postpone this to the commit release path, since no packets\nare walking over this object, this is accessed from control plane only.\nThis helped uncovered UAF triggered by races with the netlink notifier.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-362"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:17Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-3px8-2p4q-xpwm/GHSA-3px8-2p4q-xpwm.json b/advisories/unreviewed/2025/05/GHSA-3px8-2p4q-xpwm/GHSA-3px8-2p4q-xpwm.json
new file mode 100644
index 00000000000..d6dd8f5a00f
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-3px8-2p4q-xpwm/GHSA-3px8-2p4q-xpwm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3px8-2p4q-xpwm",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47664"
+ ],
+ "details": "Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a through 1.4.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47664"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-pipes/vulnerability/wordpress-wp-pipes-1-4-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-3qgh-jp39-263h/GHSA-3qgh-jp39-263h.json b/advisories/unreviewed/2025/05/GHSA-3qgh-jp39-263h/GHSA-3qgh-jp39-263h.json
new file mode 100644
index 00000000000..853756add26
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-3qgh-jp39-263h/GHSA-3qgh-jp39-263h.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3qgh-jp39-263h",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47517"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal allows Stored XSS. This issue affects Accept Donations with PayPal: from n/a through 1.4.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47517"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/easy-paypal-donation/vulnerability/wordpress-accept-donations-with-paypal-plugin-1-4-5-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-3v68-wgp5-q8w6/GHSA-3v68-wgp5-q8w6.json b/advisories/unreviewed/2025/05/GHSA-3v68-wgp5-q8w6/GHSA-3v68-wgp5-q8w6.json
new file mode 100644
index 00000000000..d4a7af3509d
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-3v68-wgp5-q8w6/GHSA-3v68-wgp5-q8w6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3v68-wgp5-q8w6",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47509"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Top 10 allows Stored XSS. This issue affects Top 10: from n/a through 4.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47509"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/top-10/vulnerability/wordpress-top-10-4-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-3xgc-7mw7-pvhp/GHSA-3xgc-7mw7-pvhp.json b/advisories/unreviewed/2025/05/GHSA-3xgc-7mw7-pvhp/GHSA-3xgc-7mw7-pvhp.json
new file mode 100644
index 00000000000..c04d0fbd21f
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-3xgc-7mw7-pvhp/GHSA-3xgc-7mw7-pvhp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3xgc-7mw7-pvhp",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47549"
+ ],
+ "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF allows Upload a Web Shell to a Web Server. This issue affects BEAF: from n/a through 4.6.10.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47549"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/beaf-before-and-after-gallery/vulnerability/wordpress-beaf-4-6-10-arbitrary-file-upload-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-434"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-44r5-hqjj-5rcx/GHSA-44r5-hqjj-5rcx.json b/advisories/unreviewed/2025/05/GHSA-44r5-hqjj-5rcx/GHSA-44r5-hqjj-5rcx.json
new file mode 100644
index 00000000000..ed0ffd5822f
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-44r5-hqjj-5rcx/GHSA-44r5-hqjj-5rcx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-44r5-hqjj-5rcx",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47515"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Seb WP DPE-GES allows DOM-Based XSS. This issue affects WP DPE-GES: from n/a through 1.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47515"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-dpe-ges/vulnerability/wordpress-wp-dpe-ges-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-4623-789q-gq79/GHSA-4623-789q-gq79.json b/advisories/unreviewed/2025/05/GHSA-4623-789q-gq79/GHSA-4623-789q-gq79.json
new file mode 100644
index 00000000000..94f61e222ed
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-4623-789q-gq79/GHSA-4623-789q-gq79.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4623-789q-gq79",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47591"
+ ],
+ "details": "Missing Authorization vulnerability in CreedAlly Bulk Featured Image allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Featured Image: from n/a through 1.2.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47591"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/bulk-featured-image/vulnerability/wordpress-bulk-featured-image-1-2-1-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-4g9q-6gcq-f3vx/GHSA-4g9q-6gcq-f3vx.json b/advisories/unreviewed/2025/05/GHSA-4g9q-6gcq-f3vx/GHSA-4g9q-6gcq-f3vx.json
index 298eb4e3342..7b6faa34664 100644
--- a/advisories/unreviewed/2025/05/GHSA-4g9q-6gcq-f3vx/GHSA-4g9q-6gcq-f3vx.json
+++ b/advisories/unreviewed/2025/05/GHSA-4g9q-6gcq-f3vx/GHSA-4g9q-6gcq-f3vx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4g9q-6gcq-f3vx",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49891"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: kprobe: Fix memory leak in test_gen_kprobe/kretprobe_cmd()\n\ntest_gen_kprobe_cmd() only free buf in fail path, hence buf will leak\nwhen there is no failure. Move kfree(buf) from fail path to common path\nto prevent the memleak. The same reason and solution in\ntest_gen_kretprobe_cmd().\n\nunreferenced object 0xffff888143b14000 (size 2048):\n comm \"insmod\", pid 52490, jiffies 4301890980 (age 40.553s)\n hex dump (first 32 bytes):\n 70 3a 6b 70 72 6f 62 65 73 2f 67 65 6e 5f 6b 70 p:kprobes/gen_kp\n 72 6f 62 65 5f 74 65 73 74 20 64 6f 5f 73 79 73 robe_test do_sys\n backtrace:\n [<000000006d7b836b>] kmalloc_trace+0x27/0xa0\n [<0000000009528b5b>] 0xffffffffa059006f\n [<000000008408b580>] do_one_initcall+0x87/0x2a0\n [<00000000c4980a7e>] do_init_module+0xdf/0x320\n [<00000000d775aad0>] load_module+0x3006/0x3390\n [<00000000e9a74b80>] __do_sys_finit_module+0x113/0x1b0\n [<000000003726480d>] do_syscall_64+0x35/0x80\n [<000000003441e93b>] entry_SYSCALL_64_after_hwframe+0x46/0xb0",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:14Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-4jm9-g5r9-6cj9/GHSA-4jm9-g5r9-6cj9.json b/advisories/unreviewed/2025/05/GHSA-4jm9-g5r9-6cj9/GHSA-4jm9-g5r9-6cj9.json
new file mode 100644
index 00000000000..3c059bc2174
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-4jm9-g5r9-6cj9/GHSA-4jm9-g5r9-6cj9.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4jm9-g5r9-6cj9",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47587"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows Blind SQL Injection. This issue affects YaySMTP: from n/a through 2.6.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47587"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/yaysmtp/vulnerability/wordpress-yaysmtp-2-6-4-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-4m6m-m354-7cfg/GHSA-4m6m-m354-7cfg.json b/advisories/unreviewed/2025/05/GHSA-4m6m-m354-7cfg/GHSA-4m6m-m354-7cfg.json
new file mode 100644
index 00000000000..35992f832d5
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-4m6m-m354-7cfg/GHSA-4m6m-m354-7cfg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4m6m-m354-7cfg",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47602"
+ ],
+ "details": "Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Calculate Prices based on Distance For WooCommerce: from n/a through 1.3.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47602"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/calculate-prices-based-on-distance-for-woocommerce/vulnerability/wordpress-calculate-prices-based-on-distance-for-woocommerce-1-3-5-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-4pm8-5w34-q28w/GHSA-4pm8-5w34-q28w.json b/advisories/unreviewed/2025/05/GHSA-4pm8-5w34-q28w/GHSA-4pm8-5w34-q28w.json
new file mode 100644
index 00000000000..57d895b56fe
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-4pm8-5w34-q28w/GHSA-4pm8-5w34-q28w.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4pm8-5w34-q28w",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47644"
+ ],
+ "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integrations of Zoho CRM with Elementor form allows Phishing. This issue affects Integrations of Zoho CRM with Elementor form: from n/a through 1.0.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47644"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/integrations-of-zoho-crm-with-elementor-form/vulnerability/wordpress-integrations-of-zoho-crm-with-elementor-form-1-0-7-open-redirection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-601"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-4pmq-325h-rx32/GHSA-4pmq-325h-rx32.json b/advisories/unreviewed/2025/05/GHSA-4pmq-325h-rx32/GHSA-4pmq-325h-rx32.json
index e8714ff16d2..406f10db506 100644
--- a/advisories/unreviewed/2025/05/GHSA-4pmq-325h-rx32/GHSA-4pmq-325h-rx32.json
+++ b/advisories/unreviewed/2025/05/GHSA-4pmq-325h-rx32/GHSA-4pmq-325h-rx32.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pmq-325h-rx32",
- "modified": "2025-05-01T15:31:52Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:52Z",
"aliases": [
"CVE-2022-49906"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nibmvnic: Free rwi on reset success\n\nFree the rwi structure in the event that the last rwi in the list\nprocessed successfully. The logic in commit 4f408e1fa6e1 (\"ibmvnic:\nretry reset if there are no other resets\") introduces an issue that\nresults in a 32 byte memory leak whenever the last rwi in the list\ngets processed.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:15Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-4wjg-xhvf-4vqf/GHSA-4wjg-xhvf-4vqf.json b/advisories/unreviewed/2025/05/GHSA-4wjg-xhvf-4vqf/GHSA-4wjg-xhvf-4vqf.json
new file mode 100644
index 00000000000..e145d94039f
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-4wjg-xhvf-4vqf/GHSA-4wjg-xhvf-4vqf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4wjg-xhvf-4vqf",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47451"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Product Quantity Dropdown For Woocommerce allows Cross Site Request Forgery. This issue affects Product Quantity Dropdown For Woocommerce: from n/a through 1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47451"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/product-quantity-dropdown-for-woocommerce/vulnerability/wordpress-product-quantity-dropdown-for-woocommerce-plugin-1-2-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:59Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-54p7-6g3w-c6qg/GHSA-54p7-6g3w-c6qg.json b/advisories/unreviewed/2025/05/GHSA-54p7-6g3w-c6qg/GHSA-54p7-6g3w-c6qg.json
new file mode 100644
index 00000000000..a99f7bd070c
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-54p7-6g3w-c6qg/GHSA-54p7-6g3w-c6qg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-54p7-6g3w-c6qg",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47497"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepoints Logo Showcase allows DOM-Based XSS. This issue affects Logo Showcase: from n/a through 3.0.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47497"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/logo-showcase/vulnerability/wordpress-logo-showcase-3-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-556p-x5xm-gmm4/GHSA-556p-x5xm-gmm4.json b/advisories/unreviewed/2025/05/GHSA-556p-x5xm-gmm4/GHSA-556p-x5xm-gmm4.json
new file mode 100644
index 00000000000..be80662dff1
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-556p-x5xm-gmm4/GHSA-556p-x5xm-gmm4.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-556p-x5xm-gmm4",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47516"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Time Clock allows Stored XSS. This issue affects Time Clock: from n/a through 1.2.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47516"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/time-clock/vulnerability/wordpress-time-clock-1-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-57jw-5h75-6jp7/GHSA-57jw-5h75-6jp7.json b/advisories/unreviewed/2025/05/GHSA-57jw-5h75-6jp7/GHSA-57jw-5h75-6jp7.json
new file mode 100644
index 00000000000..c104e818f89
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-57jw-5h75-6jp7/GHSA-57jw-5h75-6jp7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-57jw-5h75-6jp7",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47683"
+ ],
+ "details": "Deserialization of Untrusted Data vulnerability in Florent Maillefaud WP Maintenance allows Object Injection. This issue affects WP Maintenance: from n/a through 6.1.9.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47683"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-maintenance/vulnerability/wordpress-wp-maintenance-6-1-9-7-php-object-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-5fq6-9g2x-qxj3/GHSA-5fq6-9g2x-qxj3.json b/advisories/unreviewed/2025/05/GHSA-5fq6-9g2x-qxj3/GHSA-5fq6-9g2x-qxj3.json
new file mode 100644
index 00000000000..934f7f24ca0
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-5fq6-9g2x-qxj3/GHSA-5fq6-9g2x-qxj3.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5fq6-9g2x-qxj3",
+ "modified": "2025-05-07T15:31:49Z",
+ "published": "2025-05-07T15:31:49Z",
+ "aliases": [
+ "CVE-2025-47688"
+ ],
+ "details": "Missing Authorization vulnerability in Saad Iqbal Advanced File Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced File Manager: from n/a through 5.3.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47688"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/file-manager-advanced/vulnerability/wordpress-advanced-file-manager-plugin-5-3-1-broken-access-control-to-notice-dismissal-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-5gp6-334q-267g/GHSA-5gp6-334q-267g.json b/advisories/unreviewed/2025/05/GHSA-5gp6-334q-267g/GHSA-5gp6-334q-267g.json
index 1cf967e55ef..6c0a1d4d4c2 100644
--- a/advisories/unreviewed/2025/05/GHSA-5gp6-334q-267g/GHSA-5gp6-334q-267g.json
+++ b/advisories/unreviewed/2025/05/GHSA-5gp6-334q-267g/GHSA-5gp6-334q-267g.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gp6-334q-267g",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:27Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49921"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: Fix use after free in red_enqueue()\n\nWe can't use \"skb\" again after passing it to qdisc_enqueue(). This is\nbasically identical to commit 2f09707d0c97 (\"sch_sfb: Also store skb\nlen before calling child enqueue\").",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:17Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-5pxm-fr3g-jf32/GHSA-5pxm-fr3g-jf32.json b/advisories/unreviewed/2025/05/GHSA-5pxm-fr3g-jf32/GHSA-5pxm-fr3g-jf32.json
new file mode 100644
index 00000000000..cafdd3e2d35
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-5pxm-fr3g-jf32/GHSA-5pxm-fr3g-jf32.json
@@ -0,0 +1,61 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5pxm-fr3g-jf32",
+ "modified": "2025-05-07T15:31:41Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2020-36791"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: keep alloc_hash updated after hash allocation\n\nIn commit 599be01ee567 (\"net_sched: fix an OOB access in cls_tcindex\")\nI moved cp->hash calculation before the first\ntcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched.\nThis difference could lead to another out of bound access.\n\ncp->alloc_hash should always be the size allocated, we should\nupdate it after this tcindex_alloc_perfect_hash().",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36791"
+ },
+ {
+ "type": "WEB",
+ "url": "https://blog.cdthoughts.ch/2021/03/16/syzbot-bug.html"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0d1c3530e1bd38382edef72591b78e877e0edcd3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/557d015ffb27b672e24e6ad141fd887783871dc2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9f8b6c44be178c2498a00b270872a6e30e7c8266"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bd3ee8fb6371b45c71c9345cc359b94da2ddefa9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c4453d2833671e3a9f6bd52f0f581056c3736386"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d23faf32e577922b6da20bf3740625c1105381bf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6cdc5bb19b595486fb2e6661e5138d73a57f454"
+ },
+ {
+ "type": "WEB",
+ "url": "https://syzkaller.appspot.com/bug?id=ea260693da894e7b078d18fca2c9c0a19b457534"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T14:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-5q7j-4fw2-f268/GHSA-5q7j-4fw2-f268.json b/advisories/unreviewed/2025/05/GHSA-5q7j-4fw2-f268/GHSA-5q7j-4fw2-f268.json
index 397e8492f52..8f0e0e94324 100644
--- a/advisories/unreviewed/2025/05/GHSA-5q7j-4fw2-f268/GHSA-5q7j-4fw2-f268.json
+++ b/advisories/unreviewed/2025/05/GHSA-5q7j-4fw2-f268/GHSA-5q7j-4fw2-f268.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q7j-4fw2-f268",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49874"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hyperv: fix possible memory leak in mousevsc_probe()\n\nIf hid_add_device() returns error, it should call hid_destroy_device()\nto free hid_dev which is allocated in hid_allocate_device().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:12Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-5vw8-85vg-44pp/GHSA-5vw8-85vg-44pp.json b/advisories/unreviewed/2025/05/GHSA-5vw8-85vg-44pp/GHSA-5vw8-85vg-44pp.json
new file mode 100644
index 00000000000..f854312fa0f
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-5vw8-85vg-44pp/GHSA-5vw8-85vg-44pp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5vw8-85vg-44pp",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47459"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in XpeedStudio WP Fundraising Donation and Crowdfunding Platform allows Cross Site Request Forgery. This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.7.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47459"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-fundraising-donation/vulnerability/wordpress-wp-fundraising-donation-and-crowdfunding-platform-1-7-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:59Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-5w74-h8v5-q653/GHSA-5w74-h8v5-q653.json b/advisories/unreviewed/2025/05/GHSA-5w74-h8v5-q653/GHSA-5w74-h8v5-q653.json
index de747bd8dff..47cbce36fca 100644
--- a/advisories/unreviewed/2025/05/GHSA-5w74-h8v5-q653/GHSA-5w74-h8v5-q653.json
+++ b/advisories/unreviewed/2025/05/GHSA-5w74-h8v5-q653/GHSA-5w74-h8v5-q653.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5w74-h8v5-q653",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49854"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp: Fix an error handling path in mctp_init()\n\nIf mctp_neigh_init() return error, the routes resources should\nbe released in the error handling path. Otherwise some resources\nleak.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:08Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-5w7x-vhpr-4w9j/GHSA-5w7x-vhpr-4w9j.json b/advisories/unreviewed/2025/05/GHSA-5w7x-vhpr-4w9j/GHSA-5w7x-vhpr-4w9j.json
new file mode 100644
index 00000000000..145a31106d2
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-5w7x-vhpr-4w9j/GHSA-5w7x-vhpr-4w9j.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5w7x-vhpr-4w9j",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47468"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in hashthemes Hash Form allows Cross Site Request Forgery. This issue affects Hash Form: from n/a through 1.2.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47468"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/hash-form/vulnerability/wordpress-hash-form-1-2-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-5www-xw6c-xq5p/GHSA-5www-xw6c-xq5p.json b/advisories/unreviewed/2025/05/GHSA-5www-xw6c-xq5p/GHSA-5www-xw6c-xq5p.json
new file mode 100644
index 00000000000..31585c384f3
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-5www-xw6c-xq5p/GHSA-5www-xw6c-xq5p.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5www-xw6c-xq5p",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47471"
+ ],
+ "details": "Missing Authorization vulnerability in EnvoThemes Envo Extra allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Envo Extra: from n/a through 1.9.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47471"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/envo-extra/vulnerability/wordpress-envo-extra-1-9-9-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-5xrr-4hfr-g6wh/GHSA-5xrr-4hfr-g6wh.json b/advisories/unreviewed/2025/05/GHSA-5xrr-4hfr-g6wh/GHSA-5xrr-4hfr-g6wh.json
new file mode 100644
index 00000000000..838852cf359
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-5xrr-4hfr-g6wh/GHSA-5xrr-4hfr-g6wh.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5xrr-4hfr-g6wh",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47626"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in apasionados Submission DOM tracking for Contact Form 7 allows Stored XSS. This issue affects Submission DOM tracking for Contact Form 7: from n/a through 2.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47626"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/cf7-submission-dom-tracking/vulnerability/wordpress-submission-dom-tracking-for-contact-form-7-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-6555-7w66-v874/GHSA-6555-7w66-v874.json b/advisories/unreviewed/2025/05/GHSA-6555-7w66-v874/GHSA-6555-7w66-v874.json
index d6f2e6e8e01..29bba53fe8a 100644
--- a/advisories/unreviewed/2025/05/GHSA-6555-7w66-v874/GHSA-6555-7w66-v874.json
+++ b/advisories/unreviewed/2025/05/GHSA-6555-7w66-v874/GHSA-6555-7w66-v874.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6555-7w66-v874",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49861"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: mv_xor_v2: Fix a resource leak in mv_xor_v2_remove()\n\nA clk_prepare_enable() call in the probe is not balanced by a corresponding\nclk_disable_unprepare() in the remove function.\n\nAdd the missing call.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -49,7 +54,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:09Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-6cmp-hmx3-m4rx/GHSA-6cmp-hmx3-m4rx.json b/advisories/unreviewed/2025/05/GHSA-6cmp-hmx3-m4rx/GHSA-6cmp-hmx3-m4rx.json
index 1540848ca32..f16bf382e04 100644
--- a/advisories/unreviewed/2025/05/GHSA-6cmp-hmx3-m4rx/GHSA-6cmp-hmx3-m4rx.json
+++ b/advisories/unreviewed/2025/05/GHSA-6cmp-hmx3-m4rx/GHSA-6cmp-hmx3-m4rx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cmp-hmx3-m4rx",
- "modified": "2025-05-01T15:31:49Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49845"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: j1939_send_one(): fix missing CAN header initialization\n\nThe read access to struct canxl_frame::len inside of a j1939 created\nskbuff revealed a missing initialization of reserved and later filled\nelements in struct can_frame.\n\nThis patch initializes the 8 byte CAN header with zero.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:08Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-6fmv-c3mq-xjpq/GHSA-6fmv-c3mq-xjpq.json b/advisories/unreviewed/2025/05/GHSA-6fmv-c3mq-xjpq/GHSA-6fmv-c3mq-xjpq.json
index 8a3ac3d6737..2225ddf08dc 100644
--- a/advisories/unreviewed/2025/05/GHSA-6fmv-c3mq-xjpq/GHSA-6fmv-c3mq-xjpq.json
+++ b/advisories/unreviewed/2025/05/GHSA-6fmv-c3mq-xjpq/GHSA-6fmv-c3mq-xjpq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6fmv-c3mq-xjpq",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:27Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49922"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nfcmrvl: Fix potential memory leak in nfcmrvl_i2c_nci_send()\n\nnfcmrvl_i2c_nci_send() will be called by nfcmrvl_nci_send(), and skb\nshould be freed in nfcmrvl_i2c_nci_send(). However, nfcmrvl_nci_send()\nwill only free skb when i2c_master_send() return >=0, which means skb\nwill memleak when i2c_master_send() failed. Free skb no matter whether\ni2c_master_send() succeeds.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:17Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-6jpf-q9v3-x26h/GHSA-6jpf-q9v3-x26h.json b/advisories/unreviewed/2025/05/GHSA-6jpf-q9v3-x26h/GHSA-6jpf-q9v3-x26h.json
new file mode 100644
index 00000000000..9c2824099af
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-6jpf-q9v3-x26h/GHSA-6jpf-q9v3-x26h.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6jpf-q9v3-x26h",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47506"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Contextual Related Posts allows DOM-Based XSS. This issue affects Contextual Related Posts: from n/a through 4.0.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47506"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/contextual-related-posts/vulnerability/wordpress-contextual-related-posts-4-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-6qc4-p4jr-r7r2/GHSA-6qc4-p4jr-r7r2.json b/advisories/unreviewed/2025/05/GHSA-6qc4-p4jr-r7r2/GHSA-6qc4-p4jr-r7r2.json
new file mode 100644
index 00000000000..0896fcc1d34
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-6qc4-p4jr-r7r2/GHSA-6qc4-p4jr-r7r2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6qc4-p4jr-r7r2",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47551"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in ctltwp Wiki Embed allows Cross Site Request Forgery. This issue affects Wiki Embed: from n/a through 1.4.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47551"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wiki-embed/vulnerability/wordpress-wiki-embed-plugin-1-4-6-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-6qgr-97mx-84hr/GHSA-6qgr-97mx-84hr.json b/advisories/unreviewed/2025/05/GHSA-6qgr-97mx-84hr/GHSA-6qgr-97mx-84hr.json
index 00a68a40ad7..4d9f3e5a193 100644
--- a/advisories/unreviewed/2025/05/GHSA-6qgr-97mx-84hr/GHSA-6qgr-97mx-84hr.json
+++ b/advisories/unreviewed/2025/05/GHSA-6qgr-97mx-84hr/GHSA-6qgr-97mx-84hr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6qgr-97mx-84hr",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49880"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix warning in 'ext4_da_release_space'\n\nSyzkaller report issue as follows:\nEXT4-fs (loop0): Free/Dirty block details\nEXT4-fs (loop0): free_blocks=0\nEXT4-fs (loop0): dirty_blocks=0\nEXT4-fs (loop0): Block reservation details\nEXT4-fs (loop0): i_reserved_data_blocks=0\nEXT4-fs warning (device loop0): ext4_da_release_space:1527: ext4_da_release_space: ino 18, to_free 1 with only 0 reserved data blocks\n------------[ cut here ]------------\nWARNING: CPU: 0 PID: 92 at fs/ext4/inode.c:1528 ext4_da_release_space+0x25e/0x370 fs/ext4/inode.c:1524\nModules linked in:\nCPU: 0 PID: 92 Comm: kworker/u4:4 Not tainted 6.0.0-syzkaller-09423-g493ffd6605b2 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022\nWorkqueue: writeback wb_workfn (flush-7:0)\nRIP: 0010:ext4_da_release_space+0x25e/0x370 fs/ext4/inode.c:1528\nRSP: 0018:ffffc900015f6c90 EFLAGS: 00010296\nRAX: 42215896cd52ea00 RBX: 0000000000000000 RCX: 42215896cd52ea00\nRDX: 0000000000000000 RSI: 0000000080000001 RDI: 0000000000000000\nRBP: 1ffff1100e907d96 R08: ffffffff816aa79d R09: fffff520002bece5\nR10: fffff520002bece5 R11: 1ffff920002bece4 R12: ffff888021fd2000\nR13: ffff88807483ecb0 R14: 0000000000000001 R15: ffff88807483e740\nFS: 0000000000000000(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005555569ba628 CR3: 000000000c88e000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n ext4_es_remove_extent+0x1ab/0x260 fs/ext4/extents_status.c:1461\n mpage_release_unused_pages+0x24d/0xef0 fs/ext4/inode.c:1589\n ext4_writepages+0x12eb/0x3be0 fs/ext4/inode.c:2852\n do_writepages+0x3c3/0x680 mm/page-writeback.c:2469\n __writeback_single_inode+0xd1/0x670 fs/fs-writeback.c:1587\n writeback_sb_inodes+0xb3b/0x18f0 fs/fs-writeback.c:1870\n wb_writeback+0x41f/0x7b0 fs/fs-writeback.c:2044\n wb_do_writeback fs/fs-writeback.c:2187 [inline]\n wb_workfn+0x3cb/0xef0 fs/fs-writeback.c:2227\n process_one_work+0x877/0xdb0 kernel/workqueue.c:2289\n worker_thread+0xb14/0x1330 kernel/workqueue.c:2436\n kthread+0x266/0x300 kernel/kthread.c:376\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306\n \n\nAbove issue may happens as follows:\next4_da_write_begin\n ext4_create_inline_data\n ext4_clear_inode_flag(inode, EXT4_INODE_EXTENTS);\n ext4_set_inode_flag(inode, EXT4_INODE_INLINE_DATA);\n__ext4_ioctl\n ext4_ext_migrate -> will lead to eh->eh_entries not zero, and set extent flag\next4_da_write_begin\n ext4_da_convert_inline_data_to_extent\n ext4_da_write_inline_data_begin\n ext4_da_map_blocks\n ext4_insert_delayed_block\n\t if (!ext4_es_scan_clu(inode, &ext4_es_is_delonly, lblk))\n\t if (!ext4_es_scan_clu(inode, &ext4_es_is_mapped, lblk))\n\t ext4_clu_mapped(inode, EXT4_B2C(sbi, lblk)); -> will return 1\n\t allocated = true;\n ext4_es_insert_delayed_block(inode, lblk, allocated);\next4_writepages\n mpage_map_and_submit_extent(handle, &mpd, &give_up_on_write); -> return -ENOSPC\n mpage_release_unused_pages(&mpd, give_up_on_write); -> give_up_on_write == 1\n ext4_es_remove_extent\n ext4_da_release_space(inode, reserved);\n if (unlikely(to_free > ei->i_reserved_data_blocks))\n\t -> to_free == 1 but ei->i_reserved_data_blocks == 0\n\t -> then trigger warning as above\n\nTo solve above issue, forbid inode do migrate which has inline data.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -49,7 +54,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:12Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-6r2g-mfv9-3vr8/GHSA-6r2g-mfv9-3vr8.json b/advisories/unreviewed/2025/05/GHSA-6r2g-mfv9-3vr8/GHSA-6r2g-mfv9-3vr8.json
new file mode 100644
index 00000000000..9fd91fab6ff
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-6r2g-mfv9-3vr8/GHSA-6r2g-mfv9-3vr8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6r2g-mfv9-3vr8",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47485"
+ ],
+ "details": "Missing Authorization vulnerability in CozyThemes Cozy Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cozy Blocks: from n/a through 2.1.22.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47485"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/cozy-addons/vulnerability/wordpress-cozy-blocks-2-1-22-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-6v7h-jp3c-jxjm/GHSA-6v7h-jp3c-jxjm.json b/advisories/unreviewed/2025/05/GHSA-6v7h-jp3c-jxjm/GHSA-6v7h-jp3c-jxjm.json
new file mode 100644
index 00000000000..7cd504a8177
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-6v7h-jp3c-jxjm/GHSA-6v7h-jp3c-jxjm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6v7h-jp3c-jxjm",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47449"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Meow Gallery allows Stored XSS. This issue affects Meow Gallery: from n/a through 5.2.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47449"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/meow-gallery/vulnerability/wordpress-meow-gallery-5-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:59Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-6vr6-r6mg-9m3f/GHSA-6vr6-r6mg-9m3f.json b/advisories/unreviewed/2025/05/GHSA-6vr6-r6mg-9m3f/GHSA-6vr6-r6mg-9m3f.json
index b5110c7f687..7958aec1100 100644
--- a/advisories/unreviewed/2025/05/GHSA-6vr6-r6mg-9m3f/GHSA-6vr6-r6mg-9m3f.json
+++ b/advisories/unreviewed/2025/05/GHSA-6vr6-r6mg-9m3f/GHSA-6vr6-r6mg-9m3f.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6vr6-r6mg-9m3f",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:28Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49931"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Correctly move list in sc_disable()\n\nCommit 13bac861952a (\"IB/hfi1: Fix abba locking issue with sc_disable()\")\nincorrectly tries to move a list from one list head to another. The\nresult is a kernel crash.\n\nThe crash is triggered when a link goes down and there are waiters for a\nsend to complete. The following signature is seen:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000030\n [...]\n Call Trace:\n sc_disable+0x1ba/0x240 [hfi1]\n pio_freeze+0x3d/0x60 [hfi1]\n handle_freeze+0x27/0x1b0 [hfi1]\n process_one_work+0x1b0/0x380\n ? process_one_work+0x380/0x380\n worker_thread+0x30/0x360\n ? process_one_work+0x380/0x380\n kthread+0xd7/0x100\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x1f/0x30\n\nThe fix is to use the correct call to move the list.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:19Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-6xrp-v9gf-f7mv/GHSA-6xrp-v9gf-f7mv.json b/advisories/unreviewed/2025/05/GHSA-6xrp-v9gf-f7mv/GHSA-6xrp-v9gf-f7mv.json
index 62bea12b4d4..8b2c9ca9722 100644
--- a/advisories/unreviewed/2025/05/GHSA-6xrp-v9gf-f7mv/GHSA-6xrp-v9gf-f7mv.json
+++ b/advisories/unreviewed/2025/05/GHSA-6xrp-v9gf-f7mv/GHSA-6xrp-v9gf-f7mv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6xrp-v9gf-f7mv",
- "modified": "2025-05-01T15:31:52Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:52Z",
"aliases": [
"CVE-2022-49899"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: stop using keyrings subsystem for fscrypt_master_key\n\nThe approach of fs/crypto/ internally managing the fscrypt_master_key\nstructs as the payloads of \"struct key\" objects contained in a\n\"struct key\" keyring has outlived its usefulness. The original idea was\nto simplify the code by reusing code from the keyrings subsystem.\nHowever, several issues have arisen that can't easily be resolved:\n\n- When a master key struct is destroyed, blk_crypto_evict_key() must be\n called on any per-mode keys embedded in it. (This started being the\n case when inline encryption support was added.) Yet, the keyrings\n subsystem can arbitrarily delay the destruction of keys, even past the\n time the filesystem was unmounted. Therefore, currently there is no\n easy way to call blk_crypto_evict_key() when a master key is\n destroyed. Currently, this is worked around by holding an extra\n reference to the filesystem's request_queue(s). But it was overlooked\n that the request_queue reference is *not* guaranteed to pin the\n corresponding blk_crypto_profile too; for device-mapper devices that\n support inline crypto, it doesn't. This can cause a use-after-free.\n\n- When the last inode that was using an incompletely-removed master key\n is evicted, the master key removal is completed by removing the key\n struct from the keyring. Currently this is done via key_invalidate().\n Yet, key_invalidate() takes the key semaphore. This can deadlock when\n called from the shrinker, since in fscrypt_ioctl_add_key(), memory is\n allocated with GFP_KERNEL under the same semaphore.\n\n- More generally, the fact that the keyrings subsystem can arbitrarily\n delay the destruction of keys (via garbage collection delay, or via\n random processes getting temporary key references) is undesirable, as\n it means we can't strictly guarantee that all secrets are ever wiped.\n\n- Doing the master key lookups via the keyrings subsystem results in the\n key_permission LSM hook being called. fscrypt doesn't want this, as\n all access control for encrypted files is designed to happen via the\n files themselves, like any other files. The workaround which SELinux\n users are using is to change their SELinux policy to grant key search\n access to all domains. This works, but it is an odd extra step that\n shouldn't really have to be done.\n\nThe fix for all these issues is to change the implementation to what I\nshould have done originally: don't use the keyrings subsystem to keep\ntrack of the filesystem's fscrypt_master_key structs. Instead, just\nstore them in a regular kernel data structure, and rework the reference\ncounting, locking, and lifetime accordingly. Retain support for\nRCU-mode key lookups by using a hash table. Replace fscrypt_sb_free()\nwith fscrypt_sb_delete(), which releases the keys synchronously and runs\na bit earlier during unmount, so that block devices are still available.\n\nA side effect of this patch is that neither the master keys themselves\nnor the filesystem keyrings will be listed in /proc/keys anymore.\n(\"Master key users\" and the master key users keyrings will still be\nlisted.) However, this was mostly an implementation detail, and it was\nintended just for debugging purposes. I don't know of anyone using it.\n\nThis patch does *not* change how \"master key users\" (->mk_users) works;\nthat still uses the keyrings subsystem. That is still needed for key\nquotas, and changing that isn't necessary to solve the issues listed\nabove. If we decide to change that too, it would be a separate patch.\n\nI've marked this as fixing the original commit that added the fscrypt\nkeyring, but as noted above the most important issue that this patch\nfixes wasn't introduced until the addition of inline encryption support.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -33,7 +38,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:14Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-72gm-xq7f-f5xx/GHSA-72gm-xq7f-f5xx.json b/advisories/unreviewed/2025/05/GHSA-72gm-xq7f-f5xx/GHSA-72gm-xq7f-f5xx.json
new file mode 100644
index 00000000000..576c952eba3
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-72gm-xq7f-f5xx/GHSA-72gm-xq7f-f5xx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-72gm-xq7f-f5xx",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47493"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks allows DOM-Based XSS. This issue affects Ultimate Blocks: from n/a through 3.2.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47493"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ultimate-blocks/vulnerability/wordpress-ultimate-blocks-3-2-9-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-734g-j34h-q4gg/GHSA-734g-j34h-q4gg.json b/advisories/unreviewed/2025/05/GHSA-734g-j34h-q4gg/GHSA-734g-j34h-q4gg.json
new file mode 100644
index 00000000000..1b0c90c1a9d
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-734g-j34h-q4gg/GHSA-734g-j34h-q4gg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-734g-j34h-q4gg",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47519"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal Events allows Cross Site Request Forgery. This issue affects Easy PayPal Events: from n/a through 1.2.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47519"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/easy-paypal-events-tickets/vulnerability/wordpress-easy-paypal-events-1-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-79gf-mr55-pw4g/GHSA-79gf-mr55-pw4g.json b/advisories/unreviewed/2025/05/GHSA-79gf-mr55-pw4g/GHSA-79gf-mr55-pw4g.json
index 1d8e49cf42f..a03fe6d36f3 100644
--- a/advisories/unreviewed/2025/05/GHSA-79gf-mr55-pw4g/GHSA-79gf-mr55-pw4g.json
+++ b/advisories/unreviewed/2025/05/GHSA-79gf-mr55-pw4g/GHSA-79gf-mr55-pw4g.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79gf-mr55-pw4g",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49846"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Fix a slab-out-of-bounds write bug in udf_find_entry()\n\nSyzbot reported a slab-out-of-bounds Write bug:\n\nloop0: detected capacity change from 0 to 2048\n==================================================================\nBUG: KASAN: slab-out-of-bounds in udf_find_entry+0x8a5/0x14f0\nfs/udf/namei.c:253\nWrite of size 105 at addr ffff8880123ff896 by task syz-executor323/3610\n\nCPU: 0 PID: 3610 Comm: syz-executor323 Not tainted\n6.1.0-rc2-syzkaller-00105-gb229b6ca5abb #0\nHardware name: Google Compute Engine/Google Compute Engine, BIOS\nGoogle 10/11/2022\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1b1/0x28e lib/dump_stack.c:106\n print_address_description+0x74/0x340 mm/kasan/report.c:284\n print_report+0x107/0x1f0 mm/kasan/report.c:395\n kasan_report+0xcd/0x100 mm/kasan/report.c:495\n kasan_check_range+0x2a7/0x2e0 mm/kasan/generic.c:189\n memcpy+0x3c/0x60 mm/kasan/shadow.c:66\n udf_find_entry+0x8a5/0x14f0 fs/udf/namei.c:253\n udf_lookup+0xef/0x340 fs/udf/namei.c:309\n lookup_open fs/namei.c:3391 [inline]\n open_last_lookups fs/namei.c:3481 [inline]\n path_openat+0x10e6/0x2df0 fs/namei.c:3710\n do_filp_open+0x264/0x4f0 fs/namei.c:3740\n do_sys_openat2+0x124/0x4e0 fs/open.c:1310\n do_sys_open fs/open.c:1326 [inline]\n __do_sys_creat fs/open.c:1402 [inline]\n __se_sys_creat fs/open.c:1396 [inline]\n __x64_sys_creat+0x11f/0x160 fs/open.c:1396\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\nRIP: 0033:0x7ffab0d164d9\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89\nf7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01\nf0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffe1a7e6bb8 EFLAGS: 00000246 ORIG_RAX: 0000000000000055\nRAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007ffab0d164d9\nRDX: 00007ffab0d164d9 RSI: 0000000000000000 RDI: 0000000020000180\nRBP: 00007ffab0cd5a10 R08: 0000000000000000 R09: 0000000000000000\nR10: 00005555573552c0 R11: 0000000000000246 R12: 00007ffab0cd5aa0\nR13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n \n\nAllocated by task 3610:\n kasan_save_stack mm/kasan/common.c:45 [inline]\n kasan_set_track+0x3d/0x60 mm/kasan/common.c:52\n ____kasan_kmalloc mm/kasan/common.c:371 [inline]\n __kasan_kmalloc+0x97/0xb0 mm/kasan/common.c:380\n kmalloc include/linux/slab.h:576 [inline]\n udf_find_entry+0x7b6/0x14f0 fs/udf/namei.c:243\n udf_lookup+0xef/0x340 fs/udf/namei.c:309\n lookup_open fs/namei.c:3391 [inline]\n open_last_lookups fs/namei.c:3481 [inline]\n path_openat+0x10e6/0x2df0 fs/namei.c:3710\n do_filp_open+0x264/0x4f0 fs/namei.c:3740\n do_sys_openat2+0x124/0x4e0 fs/open.c:1310\n do_sys_open fs/open.c:1326 [inline]\n __do_sys_creat fs/open.c:1402 [inline]\n __se_sys_creat fs/open.c:1396 [inline]\n __x64_sys_creat+0x11f/0x160 fs/open.c:1396\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe buggy address belongs to the object at ffff8880123ff800\n which belongs to the cache kmalloc-256 of size 256\nThe buggy address is located 150 bytes inside of\n 256-byte region [ffff8880123ff800, ffff8880123ff900)\n\nThe buggy address belongs to the physical page:\npage:ffffea000048ff80 refcount:1 mapcount:0 mapping:0000000000000000\nindex:0x0 pfn:0x123fe\nhead:ffffea000048ff80 order:1 compound_mapcount:0 compound_pincount:0\nflags: 0xfff00000010200(slab|head|node=0|zone=1|lastcpupid=0x7ff)\nraw: 00fff00000010200 ffffea00004b8500 dead000000000003 ffff888012041b40\nraw: 0000000000000000 0000000080100010 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner tracks the page as allocated\npage last allocated via order 0, migratetype Unmovable, gfp_mask 0x0(),\npid 1, tgid 1 (swapper/0), ts 1841222404, free_ts 0\n create_dummy_stack mm/page_owner.c:\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-787"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:08Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-79q2-r662-3wfc/GHSA-79q2-r662-3wfc.json b/advisories/unreviewed/2025/05/GHSA-79q2-r662-3wfc/GHSA-79q2-r662-3wfc.json
new file mode 100644
index 00000000000..e2ea71aec3e
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-79q2-r662-3wfc/GHSA-79q2-r662-3wfc.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-79q2-r662-3wfc",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47657"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Productive Minds Productive Commerce allows SQL Injection. This issue affects Productive Commerce: from n/a through 1.1.22.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47657"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/productive-commerce/vulnerability/wordpress-productive-commerce-1-1-22-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-7crj-grwh-6247/GHSA-7crj-grwh-6247.json b/advisories/unreviewed/2025/05/GHSA-7crj-grwh-6247/GHSA-7crj-grwh-6247.json
index 19c82935721..e8984ee1f45 100644
--- a/advisories/unreviewed/2025/05/GHSA-7crj-grwh-6247/GHSA-7crj-grwh-6247.json
+++ b/advisories/unreviewed/2025/05/GHSA-7crj-grwh-6247/GHSA-7crj-grwh-6247.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7crj-grwh-6247",
- "modified": "2025-05-01T15:31:49Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49840"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, test_run: Fix alignment problem in bpf_prog_test_run_skb()\n\nWe got a syzkaller problem because of aarch64 alignment fault\nif KFENCE enabled. When the size from user bpf program is an odd\nnumber, like 399, 407, etc, it will cause the struct skb_shared_info's\nunaligned access. As seen below:\n\n BUG: KFENCE: use-after-free read in __skb_clone+0x23c/0x2a0 net/core/skbuff.c:1032\n\n Use-after-free read at 0xffff6254fffac077 (in kfence-#213):\n __lse_atomic_add arch/arm64/include/asm/atomic_lse.h:26 [inline]\n arch_atomic_add arch/arm64/include/asm/atomic.h:28 [inline]\n arch_atomic_inc include/linux/atomic-arch-fallback.h:270 [inline]\n atomic_inc include/asm-generic/atomic-instrumented.h:241 [inline]\n __skb_clone+0x23c/0x2a0 net/core/skbuff.c:1032\n skb_clone+0xf4/0x214 net/core/skbuff.c:1481\n ____bpf_clone_redirect net/core/filter.c:2433 [inline]\n bpf_clone_redirect+0x78/0x1c0 net/core/filter.c:2420\n bpf_prog_d3839dd9068ceb51+0x80/0x330\n bpf_dispatcher_nop_func include/linux/bpf.h:728 [inline]\n bpf_test_run+0x3c0/0x6c0 net/bpf/test_run.c:53\n bpf_prog_test_run_skb+0x638/0xa7c net/bpf/test_run.c:594\n bpf_prog_test_run kernel/bpf/syscall.c:3148 [inline]\n __do_sys_bpf kernel/bpf/syscall.c:4441 [inline]\n __se_sys_bpf+0xad0/0x1634 kernel/bpf/syscall.c:4381\n\n kfence-#213: 0xffff6254fffac000-0xffff6254fffac196, size=407, cache=kmalloc-512\n\n allocated by task 15074 on cpu 0 at 1342.585390s:\n kmalloc include/linux/slab.h:568 [inline]\n kzalloc include/linux/slab.h:675 [inline]\n bpf_test_init.isra.0+0xac/0x290 net/bpf/test_run.c:191\n bpf_prog_test_run_skb+0x11c/0xa7c net/bpf/test_run.c:512\n bpf_prog_test_run kernel/bpf/syscall.c:3148 [inline]\n __do_sys_bpf kernel/bpf/syscall.c:4441 [inline]\n __se_sys_bpf+0xad0/0x1634 kernel/bpf/syscall.c:4381\n __arm64_sys_bpf+0x50/0x60 kernel/bpf/syscall.c:4381\n\nTo fix the problem, we adjust @size so that (@size + @hearoom) is a\nmultiple of SMP_CACHE_BYTES. So we make sure the struct skb_shared_info\nis aligned to a cache line.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:07Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-7qcm-qx74-j7hr/GHSA-7qcm-qx74-j7hr.json b/advisories/unreviewed/2025/05/GHSA-7qcm-qx74-j7hr/GHSA-7qcm-qx74-j7hr.json
index 9f253cfeaab..4a8d1ed991d 100644
--- a/advisories/unreviewed/2025/05/GHSA-7qcm-qx74-j7hr/GHSA-7qcm-qx74-j7hr.json
+++ b/advisories/unreviewed/2025/05/GHSA-7qcm-qx74-j7hr/GHSA-7qcm-qx74-j7hr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7qcm-qx74-j7hr",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:52Z",
"aliases": [
"CVE-2022-49916"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrose: Fix NULL pointer dereference in rose_send_frame()\n\nThe syzkaller reported an issue:\n\nKASAN: null-ptr-deref in range [0x0000000000000380-0x0000000000000387]\nCPU: 0 PID: 4069 Comm: kworker/0:15 Not tainted 6.0.0-syzkaller-02734-g0326074ff465 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022\nWorkqueue: rcu_gp srcu_invoke_callbacks\nRIP: 0010:rose_send_frame+0x1dd/0x2f0 net/rose/rose_link.c:101\nCall Trace:\n \n rose_transmit_clear_request+0x1d5/0x290 net/rose/rose_link.c:255\n rose_rx_call_request+0x4c0/0x1bc0 net/rose/af_rose.c:1009\n rose_loopback_timer+0x19e/0x590 net/rose/rose_loopback.c:111\n call_timer_fn+0x1a0/0x6b0 kernel/time/timer.c:1474\n expire_timers kernel/time/timer.c:1519 [inline]\n __run_timers.part.0+0x674/0xa80 kernel/time/timer.c:1790\n __run_timers kernel/time/timer.c:1768 [inline]\n run_timer_softirq+0xb3/0x1d0 kernel/time/timer.c:1803\n __do_softirq+0x1d0/0x9c8 kernel/softirq.c:571\n [...]\n \n\nIt triggers NULL pointer dereference when 'neigh->dev->dev_addr' is\ncalled in the rose_send_frame(). It's the first occurrence of the\n`neigh` is in rose_loopback_timer() as `rose_loopback_neigh', and\nthe 'dev' in 'rose_loopback_neigh' is initialized sa nullptr.\n\nIt had been fixed by commit 3b3fd068c56e3fbea30090859216a368398e39bf\n(\"rose: Fix Null pointer dereference in rose_send_frame()\") ever.\nBut it's introduced by commit 3c53cd65dece47dd1f9d3a809f32e59d1d87b2b8\n(\"rose: check NULL rose_loopback_neigh->loopback\") again.\n\nWe fix it by add NULL check in rose_transmit_clear_request(). When\nthe 'dev' in 'neigh' is NULL, we don't reply the request and just\nclear it.\n\nsyzkaller don't provide repro, and I provide a syz repro like:\nr0 = syz_init_net_socket$bt_sco(0x1f, 0x5, 0x2)\nioctl$sock_inet_SIOCSIFFLAGS(r0, 0x8914, &(0x7f0000000180)={'rose0\\x00', 0x201})\nr1 = syz_init_net_socket$rose(0xb, 0x5, 0x0)\nbind$rose(r1, &(0x7f00000000c0)=@full={0xb, @dev, @null, 0x0, [@null, @null, @netrom, @netrom, @default, @null]}, 0x40)\nconnect$rose(r1, &(0x7f0000000240)=@short={0xb, @dev={0xbb, 0xbb, 0xbb, 0x1, 0x0}, @remote={0xcc, 0xcc, 0xcc, 0xcc, 0xcc, 0xcc, 0x1}, 0x1, @netrom={0xbb, 0xbb, 0xbb, 0xbb, 0xbb, 0x0, 0x0}}, 0x1c)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:16Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-7rp5-2xjr-qvc2/GHSA-7rp5-2xjr-qvc2.json b/advisories/unreviewed/2025/05/GHSA-7rp5-2xjr-qvc2/GHSA-7rp5-2xjr-qvc2.json
new file mode 100644
index 00000000000..dc77216c094
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-7rp5-2xjr-qvc2/GHSA-7rp5-2xjr-qvc2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7rp5-2xjr-qvc2",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:42Z",
+ "aliases": [
+ "CVE-2025-47446"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in listamester Listamester allows Cross Site Request Forgery. This issue affects Listamester: from n/a through 2.3.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47446"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/listamester/vulnerability/wordpress-listamester-2-3-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:58Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-7rqx-j7hv-hqhq/GHSA-7rqx-j7hv-hqhq.json b/advisories/unreviewed/2025/05/GHSA-7rqx-j7hv-hqhq/GHSA-7rqx-j7hv-hqhq.json
new file mode 100644
index 00000000000..8bd72691a95
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-7rqx-j7hv-hqhq/GHSA-7rqx-j7hv-hqhq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7rqx-j7hv-hqhq",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47510"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fullworks Display Eventbrite Events allows PHP Local File Inclusion. This issue affects Display Eventbrite Events: from n/a through n/a.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47510"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/widget-for-eventbrite-api/vulnerability/wordpress-display-eventbrite-events-6-3-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-7vc8-j52g-5923/GHSA-7vc8-j52g-5923.json b/advisories/unreviewed/2025/05/GHSA-7vc8-j52g-5923/GHSA-7vc8-j52g-5923.json
new file mode 100644
index 00000000000..fc4d7f6944a
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-7vc8-j52g-5923/GHSA-7vc8-j52g-5923.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7vc8-j52g-5923",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47533"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina allows PHP Local File Inclusion. This issue affects Graphina: from n/a through 3.0.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47533"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/graphina-elementor-charts-and-graphs/vulnerability/wordpress-graphina-plugin-3-0-4-cross-site-request-forgery-csrf-to-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-82pm-2p38-r95c/GHSA-82pm-2p38-r95c.json b/advisories/unreviewed/2025/05/GHSA-82pm-2p38-r95c/GHSA-82pm-2p38-r95c.json
new file mode 100644
index 00000000000..f533c5991f9
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-82pm-2p38-r95c/GHSA-82pm-2p38-r95c.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-82pm-2p38-r95c",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47502"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Mollie Forms allows Stored XSS. This issue affects Mollie Forms: from n/a through 2.7.12.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47502"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/mollie-forms/vulnerability/wordpress-mollie-forms-2-7-12-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8338-wqxp-w83r/GHSA-8338-wqxp-w83r.json b/advisories/unreviewed/2025/05/GHSA-8338-wqxp-w83r/GHSA-8338-wqxp-w83r.json
new file mode 100644
index 00000000000..c17bcd0cae5
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8338-wqxp-w83r/GHSA-8338-wqxp-w83r.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8338-wqxp-w83r",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47505"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProWCPlugins Product Time Countdown for WooCommerce allows Stored XSS. This issue affects Product Time Countdown for WooCommerce: from n/a through 1.6.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47505"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/product-countdown-for-woocommerce/vulnerability/wordpress-product-time-countdown-for-woocommerce-1-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8373-2jx7-7xq3/GHSA-8373-2jx7-7xq3.json b/advisories/unreviewed/2025/05/GHSA-8373-2jx7-7xq3/GHSA-8373-2jx7-7xq3.json
new file mode 100644
index 00000000000..34cbf2243a1
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8373-2jx7-7xq3/GHSA-8373-2jx7-7xq3.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8373-2jx7-7xq3",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47543"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker allows Cross Site Request Forgery. This issue affects TrueBooker: from n/a through 1.0.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47543"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/truebooker-appointment-booking/vulnerability/wordpress-truebooker-1-0-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-84xp-2wxp-xq57/GHSA-84xp-2wxp-xq57.json b/advisories/unreviewed/2025/05/GHSA-84xp-2wxp-xq57/GHSA-84xp-2wxp-xq57.json
index 26d2a60e33b..07ea608ba9b 100644
--- a/advisories/unreviewed/2025/05/GHSA-84xp-2wxp-xq57/GHSA-84xp-2wxp-xq57.json
+++ b/advisories/unreviewed/2025/05/GHSA-84xp-2wxp-xq57/GHSA-84xp-2wxp-xq57.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84xp-2wxp-xq57",
- "modified": "2025-05-06T12:30:23Z",
+ "modified": "2025-05-07T15:31:33Z",
"published": "2025-05-06T12:30:23Z",
"aliases": [
"CVE-2025-2011"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2011"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/datagoboom/CVE-2025-2011"
+ },
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/depicter/trunk/app/src/Controllers/Ajax/LeadsAjaxController.php?rev=3156664#L179"
diff --git a/advisories/unreviewed/2025/05/GHSA-85cg-pvgv-vxwv/GHSA-85cg-pvgv-vxwv.json b/advisories/unreviewed/2025/05/GHSA-85cg-pvgv-vxwv/GHSA-85cg-pvgv-vxwv.json
new file mode 100644
index 00000000000..1b570ea0da2
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-85cg-pvgv-vxwv/GHSA-85cg-pvgv-vxwv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-85cg-pvgv-vxwv",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47484"
+ ],
+ "details": "Server-Side Request Forgery (SSRF) vulnerability in Oliver Campion Display Remote Posts Block allows Server Side Request Forgery. This issue affects Display Remote Posts Block: from n/a through 1.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47484"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/display-remote-posts-block/vulnerability/wordpress-display-remote-posts-block-1-1-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8cr8-whqv-vm3j/GHSA-8cr8-whqv-vm3j.json b/advisories/unreviewed/2025/05/GHSA-8cr8-whqv-vm3j/GHSA-8cr8-whqv-vm3j.json
index 4b4794bfe28..091e156eba6 100644
--- a/advisories/unreviewed/2025/05/GHSA-8cr8-whqv-vm3j/GHSA-8cr8-whqv-vm3j.json
+++ b/advisories/unreviewed/2025/05/GHSA-8cr8-whqv-vm3j/GHSA-8cr8-whqv-vm3j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8cr8-whqv-vm3j",
- "modified": "2025-05-01T15:31:49Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49839"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_transport_sas: Fix error handling in sas_phy_add()\n\nIf transport_add_device() fails in sas_phy_add(), the kernel will crash\ntrying to delete the device in transport_remove_device() called from\nsas_remove_host().\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000108\nCPU: 61 PID: 42829 Comm: rmmod Kdump: loaded Tainted: G W 6.1.0-rc1+ #173\npstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : device_del+0x54/0x3d0\nlr : device_del+0x37c/0x3d0\nCall trace:\n device_del+0x54/0x3d0\n attribute_container_class_device_del+0x28/0x38\n transport_remove_classdev+0x6c/0x80\n attribute_container_device_trigger+0x108/0x110\n transport_remove_device+0x28/0x38\n sas_phy_delete+0x30/0x60 [scsi_transport_sas]\n do_sas_phy_delete+0x6c/0x80 [scsi_transport_sas]\n device_for_each_child+0x68/0xb0\n sas_remove_children+0x40/0x50 [scsi_transport_sas]\n sas_remove_host+0x20/0x38 [scsi_transport_sas]\n hisi_sas_remove+0x40/0x68 [hisi_sas_main]\n hisi_sas_v2_remove+0x20/0x30 [hisi_sas_v2_hw]\n platform_remove+0x2c/0x60\n\nFix this by checking and handling return value of transport_add_device()\nin sas_phy_add().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:07Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-8cwm-c2r5-2hp9/GHSA-8cwm-c2r5-2hp9.json b/advisories/unreviewed/2025/05/GHSA-8cwm-c2r5-2hp9/GHSA-8cwm-c2r5-2hp9.json
new file mode 100644
index 00000000000..15a53c58131
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8cwm-c2r5-2hp9/GHSA-8cwm-c2r5-2hp9.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8cwm-c2r5-2hp9",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47503"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search allows Stored XSS. This issue affects NGG Smart Image Search: from n/a through 3.3.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47503"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ngg-smart-image-search/vulnerability/wordpress-ngg-smart-image-search-3-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8f66-px45-79r5/GHSA-8f66-px45-79r5.json b/advisories/unreviewed/2025/05/GHSA-8f66-px45-79r5/GHSA-8f66-px45-79r5.json
new file mode 100644
index 00000000000..d62ead4ca21
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8f66-px45-79r5/GHSA-8f66-px45-79r5.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8f66-px45-79r5",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47482"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Skill Bar allows Stored XSS. This issue affects SKT Skill Bar: from n/a through 2.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47482"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/skt-skill-bar/vulnerability/wordpress-skt-skill-bar-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8fgm-3937-8v3v/GHSA-8fgm-3937-8v3v.json b/advisories/unreviewed/2025/05/GHSA-8fgm-3937-8v3v/GHSA-8fgm-3937-8v3v.json
new file mode 100644
index 00000000000..f1308f55f40
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8fgm-3937-8v3v/GHSA-8fgm-3937-8v3v.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8fgm-3937-8v3v",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:42Z",
+ "aliases": [
+ "CVE-2025-47447"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box allows Cross Site Request Forgery. This issue affects Cool Author Box: from n/a through 3.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47447"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/hm-cool-author-box-widget/vulnerability/wordpress-cool-author-box-3-0-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:58Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8gg5-3vh3-h338/GHSA-8gg5-3vh3-h338.json b/advisories/unreviewed/2025/05/GHSA-8gg5-3vh3-h338/GHSA-8gg5-3vh3-h338.json
new file mode 100644
index 00000000000..f09af4fb4d9
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8gg5-3vh3-h338/GHSA-8gg5-3vh3-h338.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8gg5-3vh3-h338",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47630"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Ajax Load More allows Stored XSS. This issue affects Ajax Load More: from n/a through 7.3.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47630"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ajax-load-more/vulnerability/wordpress-ajax-load-more-7-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8m6p-58m5-ghfx/GHSA-8m6p-58m5-ghfx.json b/advisories/unreviewed/2025/05/GHSA-8m6p-58m5-ghfx/GHSA-8m6p-58m5-ghfx.json
new file mode 100644
index 00000000000..4891697853a
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8m6p-58m5-ghfx/GHSA-8m6p-58m5-ghfx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8m6p-58m5-ghfx",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47526"
+ ],
+ "details": "Missing Authorization vulnerability in GS Plugins GS Variation Swatches for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GS Variation Swatches for WooCommerce: from n/a through 3.0.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47526"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gs-woo-variation-swatches/vulnerability/wordpress-gs-variation-swatches-for-woocommerce-3-0-4-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8p4g-7vvj-g5r6/GHSA-8p4g-7vvj-g5r6.json b/advisories/unreviewed/2025/05/GHSA-8p4g-7vvj-g5r6/GHSA-8p4g-7vvj-g5r6.json
index 454bd0b0520..2d4729d6c24 100644
--- a/advisories/unreviewed/2025/05/GHSA-8p4g-7vvj-g5r6/GHSA-8p4g-7vvj-g5r6.json
+++ b/advisories/unreviewed/2025/05/GHSA-8p4g-7vvj-g5r6/GHSA-8p4g-7vvj-g5r6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8p4g-7vvj-g5r6",
- "modified": "2025-05-01T15:31:52Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:52Z",
"aliases": [
"CVE-2022-49915"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: fix possible memory leak in mISDN_register_device()\n\nAfer commit 1fa5ae857bb1 (\"driver core: get rid of struct device's\nbus_id string array\"), the name of device is allocated dynamically,\nadd put_device() to give up the reference, so that the name can be\nfreed in kobject_cleanup() when the refcount is 0.\n\nSet device class before put_device() to avoid null release() function\nWARN message in device_release().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:16Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-8p4q-63f6-rqfp/GHSA-8p4q-63f6-rqfp.json b/advisories/unreviewed/2025/05/GHSA-8p4q-63f6-rqfp/GHSA-8p4q-63f6-rqfp.json
index 75e71ee9327..aa09ac72cd3 100644
--- a/advisories/unreviewed/2025/05/GHSA-8p4q-63f6-rqfp/GHSA-8p4q-63f6-rqfp.json
+++ b/advisories/unreviewed/2025/05/GHSA-8p4q-63f6-rqfp/GHSA-8p4q-63f6-rqfp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8p4q-63f6-rqfp",
- "modified": "2025-05-01T15:31:52Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:52Z",
"aliases": [
"CVE-2022-49902"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Fix possible memory leak for rq_wb on add_disk failure\n\nkmemleak reported memory leaks in device_add_disk():\n\nkmemleak: 3 new suspected memory leaks\n\nunreferenced object 0xffff88800f420800 (size 512):\n comm \"modprobe\", pid 4275, jiffies 4295639067 (age 223.512s)\n hex dump (first 32 bytes):\n 04 00 00 00 08 00 00 00 01 00 00 00 00 00 00 00 ................\n 00 e1 f5 05 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000d3662699>] kmalloc_trace+0x26/0x60\n [<00000000edc7aadc>] wbt_init+0x50/0x6f0\n [<0000000069601d16>] wbt_enable_default+0x157/0x1c0\n [<0000000028fc393f>] blk_register_queue+0x2a4/0x420\n [<000000007345a042>] device_add_disk+0x6fd/0xe40\n [<0000000060e6aab0>] nbd_dev_add+0x828/0xbf0 [nbd]\n ...\n\nIt is because the memory allocated in wbt_enable_default() is not\nreleased in device_add_disk() error path.\nNormally, these memory are freed in:\n\ndel_gendisk()\n rq_qos_exit()\n rqos->ops->exit(rqos);\n wbt_exit()\n\nSo rq_qos_exit() is called to free the rq_wb memory for wbt_init().\nHowever in the error path of device_add_disk(), only\nblk_unregister_queue() is called and make rq_wb memory leaked.\n\nAdd rq_qos_exit() to the error path to fix it.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:15Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-8pw2-4xpq-9vc8/GHSA-8pw2-4xpq-9vc8.json b/advisories/unreviewed/2025/05/GHSA-8pw2-4xpq-9vc8/GHSA-8pw2-4xpq-9vc8.json
new file mode 100644
index 00000000000..48405a74722
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8pw2-4xpq-9vc8/GHSA-8pw2-4xpq-9vc8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8pw2-4xpq-9vc8",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47655"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in themarketer2023 theMarketer allows Stored XSS. This issue affects theMarketer: from n/a through 1.4.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47655"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/themarketer/vulnerability/wordpress-themarketer-plugin-1-4-7-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8qrx-89cf-rx47/GHSA-8qrx-89cf-rx47.json b/advisories/unreviewed/2025/05/GHSA-8qrx-89cf-rx47/GHSA-8qrx-89cf-rx47.json
new file mode 100644
index 00000000000..7309d3101fc
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8qrx-89cf-rx47/GHSA-8qrx-89cf-rx47.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8qrx-89cf-rx47",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47667"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent allows Cross Site Request Forgery. This issue affects LiveAgent: from n/a through 4.4.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47667"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/liveagent/vulnerability/wordpress-liveagent-4-4-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8r5m-9xx4-3v9j/GHSA-8r5m-9xx4-3v9j.json b/advisories/unreviewed/2025/05/GHSA-8r5m-9xx4-3v9j/GHSA-8r5m-9xx4-3v9j.json
index 7ae196d9bf6..5dbfa3d651c 100644
--- a/advisories/unreviewed/2025/05/GHSA-8r5m-9xx4-3v9j/GHSA-8r5m-9xx4-3v9j.json
+++ b/advisories/unreviewed/2025/05/GHSA-8r5m-9xx4-3v9j/GHSA-8r5m-9xx4-3v9j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8r5m-9xx4-3v9j",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:27Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49920"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: netlink notifier might race to release objects\n\ncommit release path is invoked via call_rcu and it runs lockless to\nrelease the objects after rcu grace period. The netlink notifier handler\nmight win race to remove objects that the transaction context is still\nreferencing from the commit release path.\n\nCall rcu_barrier() to ensure pending rcu callbacks run to completion\nif the list of transactions to be destroyed is not empty.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-362"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:17Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-8r89-r77h-8gvm/GHSA-8r89-r77h-8gvm.json b/advisories/unreviewed/2025/05/GHSA-8r89-r77h-8gvm/GHSA-8r89-r77h-8gvm.json
index 983667b84c2..c830fbf3bce 100644
--- a/advisories/unreviewed/2025/05/GHSA-8r89-r77h-8gvm/GHSA-8r89-r77h-8gvm.json
+++ b/advisories/unreviewed/2025/05/GHSA-8r89-r77h-8gvm/GHSA-8r89-r77h-8gvm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8r89-r77h-8gvm",
- "modified": "2025-05-01T15:31:49Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49842"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: core: Fix use-after-free in snd_soc_exit()\n\nKASAN reports a use-after-free:\n\nBUG: KASAN: use-after-free in device_del+0xb5b/0xc60\nRead of size 8 at addr ffff888008655050 by task rmmod/387\nCPU: 2 PID: 387 Comm: rmmod\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996)\nCall Trace:\n\ndump_stack_lvl+0x79/0x9a\nprint_report+0x17f/0x47b\nkasan_report+0xbb/0xf0\ndevice_del+0xb5b/0xc60\nplatform_device_del.part.0+0x24/0x200\nplatform_device_unregister+0x2e/0x40\nsnd_soc_exit+0xa/0x22 [snd_soc_core]\n__do_sys_delete_module.constprop.0+0x34f/0x5b0\ndo_syscall_64+0x3a/0x90\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\n...\n\n\nIt's bacause in snd_soc_init(), snd_soc_util_init() is possble to fail,\nbut its ret is ignored, which makes soc_dummy_dev unregistered twice.\n\nsnd_soc_init()\n snd_soc_util_init()\n platform_device_register_simple(soc_dummy_dev)\n platform_driver_register() # fail\n \tplatform_device_unregister(soc_dummy_dev)\n platform_driver_register() # success\n...\nsnd_soc_exit()\n snd_soc_util_exit()\n # soc_dummy_dev will be unregistered for second time\n\nTo fix it, handle error and stop snd_soc_init() when util_init() fail.\nAlso clean debugfs when util_init() or driver_register() fail.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:07Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-8vv6-g3hv-82xh/GHSA-8vv6-g3hv-82xh.json b/advisories/unreviewed/2025/05/GHSA-8vv6-g3hv-82xh/GHSA-8vv6-g3hv-82xh.json
new file mode 100644
index 00000000000..a6e946232be
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-8vv6-g3hv-82xh/GHSA-8vv6-g3hv-82xh.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8vv6-g3hv-82xh",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47480"
+ ],
+ "details": "Missing Authorization vulnerability in Iqonic Design Graphina allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Graphina: from n/a through 3.0.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47480"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/graphina-elementor-charts-and-graphs/vulnerability/wordpress-graphina-3-0-4-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-8w66-gh7h-jgjh/GHSA-8w66-gh7h-jgjh.json b/advisories/unreviewed/2025/05/GHSA-8w66-gh7h-jgjh/GHSA-8w66-gh7h-jgjh.json
index addf97d23f5..7d3510a1d5b 100644
--- a/advisories/unreviewed/2025/05/GHSA-8w66-gh7h-jgjh/GHSA-8w66-gh7h-jgjh.json
+++ b/advisories/unreviewed/2025/05/GHSA-8w66-gh7h-jgjh/GHSA-8w66-gh7h-jgjh.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w66-gh7h-jgjh",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49894"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Fix region HPA ordering validation\n\nSome regions may not have any address space allocated. Skip them when\nvalidating HPA order otherwise a crash like the following may result:\n\n devm_cxl_add_region: cxl_acpi cxl_acpi.0: decoder3.4: created region9\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n [..]\n RIP: 0010:store_targetN+0x655/0x1740 [cxl_core]\n [..]\n Call Trace:\n \n kernfs_fop_write_iter+0x144/0x200\n vfs_write+0x24a/0x4d0\n ksys_write+0x69/0xf0\n do_syscall_64+0x3a/0x90\n\nstore_targetN+0x655/0x1740:\nalloc_region_ref at drivers/cxl/core/region.c:676\n(inlined by) cxl_port_attach_region at drivers/cxl/core/region.c:850\n(inlined by) cxl_region_attach at drivers/cxl/core/region.c:1290\n(inlined by) attach_target at drivers/cxl/core/region.c:1410\n(inlined by) store_targetN at drivers/cxl/core/region.c:1453",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:14Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-93f5-2cgj-8wfq/GHSA-93f5-2cgj-8wfq.json b/advisories/unreviewed/2025/05/GHSA-93f5-2cgj-8wfq/GHSA-93f5-2cgj-8wfq.json
new file mode 100644
index 00000000000..596c04fd86e
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-93f5-2cgj-8wfq/GHSA-93f5-2cgj-8wfq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-93f5-2cgj-8wfq",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47593"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonas Hjalmarsson Really Simple Under Construction Page allows Stored XSS. This issue affects Really Simple Under Construction Page: from n/a through 1.4.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47593"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/really-simple-under-construction/vulnerability/wordpress-really-simple-under-construction-page-1-4-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-95cr-2j94-r726/GHSA-95cr-2j94-r726.json b/advisories/unreviewed/2025/05/GHSA-95cr-2j94-r726/GHSA-95cr-2j94-r726.json
new file mode 100644
index 00000000000..39a89684fd1
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-95cr-2j94-r726/GHSA-95cr-2j94-r726.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-95cr-2j94-r726",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47470"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in senols GPT3 AI Content Writer allows Cross Site Request Forgery. This issue affects GPT3 AI Content Writer: from n/a through 1.9.14.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47470"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gpt3-ai-content-generator/vulnerability/wordpress-gpt3-ai-content-writer-plugin-1-9-14-cross-site-request-forgery-csrf-to-prompt-generation-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-95j2-mg4g-88qj/GHSA-95j2-mg4g-88qj.json b/advisories/unreviewed/2025/05/GHSA-95j2-mg4g-88qj/GHSA-95j2-mg4g-88qj.json
new file mode 100644
index 00000000000..a9efb2c488b
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-95j2-mg4g-88qj/GHSA-95j2-mg4g-88qj.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-95j2-mg4g-88qj",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47616"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tushar Imran aBlocks allows Stored XSS. This issue affects aBlocks: from n/a through 1.9.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47616"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ablocks/vulnerability/wordpress-ablocks-1-9-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-95mr-cf2h-w5jf/GHSA-95mr-cf2h-w5jf.json b/advisories/unreviewed/2025/05/GHSA-95mr-cf2h-w5jf/GHSA-95mr-cf2h-w5jf.json
index 6b4b5ff6a2f..1efa46aa197 100644
--- a/advisories/unreviewed/2025/05/GHSA-95mr-cf2h-w5jf/GHSA-95mr-cf2h-w5jf.json
+++ b/advisories/unreviewed/2025/05/GHSA-95mr-cf2h-w5jf/GHSA-95mr-cf2h-w5jf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-95mr-cf2h-w5jf",
- "modified": "2025-05-06T21:30:48Z",
+ "modified": "2025-05-07T15:31:36Z",
"published": "2025-05-06T21:30:48Z",
"aliases": [
"CVE-2025-44899"
],
"details": "There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, the manipulation of the parameter shareSpeed leads to stack overflow.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-121"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-06T21:16:19Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-965c-2m8v-wcjh/GHSA-965c-2m8v-wcjh.json b/advisories/unreviewed/2025/05/GHSA-965c-2m8v-wcjh/GHSA-965c-2m8v-wcjh.json
index 352c83db3b8..a8713ae7822 100644
--- a/advisories/unreviewed/2025/05/GHSA-965c-2m8v-wcjh/GHSA-965c-2m8v-wcjh.json
+++ b/advisories/unreviewed/2025/05/GHSA-965c-2m8v-wcjh/GHSA-965c-2m8v-wcjh.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-965c-2m8v-wcjh",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:28Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49927"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfs4: Fix kmemleak when allocate slot failed\n\nIf one of the slot allocate failed, should cleanup all the other\nallocated slots, otherwise, the allocated slots will leak:\n\n unreferenced object 0xffff8881115aa100 (size 64):\n comm \"\"mount.nfs\"\", pid 679, jiffies 4294744957 (age 115.037s)\n hex dump (first 32 bytes):\n 00 cc 19 73 81 88 ff ff 00 a0 5a 11 81 88 ff ff ...s......Z.....\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<000000007a4c434a>] nfs4_find_or_create_slot+0x8e/0x130\n [<000000005472a39c>] nfs4_realloc_slot_table+0x23f/0x270\n [<00000000cd8ca0eb>] nfs40_init_client+0x4a/0x90\n [<00000000128486db>] nfs4_init_client+0xce/0x270\n [<000000008d2cacad>] nfs4_set_client+0x1a2/0x2b0\n [<000000000e593b52>] nfs4_create_server+0x300/0x5f0\n [<00000000e4425dd2>] nfs4_try_get_tree+0x65/0x110\n [<00000000d3a6176f>] vfs_get_tree+0x41/0xf0\n [<0000000016b5ad4c>] path_mount+0x9b3/0xdd0\n [<00000000494cae71>] __x64_sys_mount+0x190/0x1d0\n [<000000005d56bdec>] do_syscall_64+0x35/0x80\n [<00000000687c9ae4>] entry_SYSCALL_64_after_hwframe+0x46/0xb0",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:18Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-9667-xm3j-4jj5/GHSA-9667-xm3j-4jj5.json b/advisories/unreviewed/2025/05/GHSA-9667-xm3j-4jj5/GHSA-9667-xm3j-4jj5.json
new file mode 100644
index 00000000000..b768eda8c2c
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-9667-xm3j-4jj5/GHSA-9667-xm3j-4jj5.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9667-xm3j-4jj5",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47639"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Supertext Supertext Translation and Proofreading allows Stored XSS. This issue affects Supertext Translation and Proofreading: from n/a through 4.25.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47639"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/polylang-supertext/vulnerability/wordpress-supertext-translation-and-proofreading-plugin-4-25-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-96c8-gqw7-x7xm/GHSA-96c8-gqw7-x7xm.json b/advisories/unreviewed/2025/05/GHSA-96c8-gqw7-x7xm/GHSA-96c8-gqw7-x7xm.json
new file mode 100644
index 00000000000..146adca40eb
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-96c8-gqw7-x7xm/GHSA-96c8-gqw7-x7xm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-96c8-gqw7-x7xm",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47481"
+ ],
+ "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS Testimonial Slider allows Code Injection. This issue affects GS Testimonial Slider: from n/a through 3.2.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47481"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gs-testimonial/vulnerability/wordpress-gs-testimonial-slider-plugin-3-2-9-content-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-94"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-9gm2-8g95-pwq8/GHSA-9gm2-8g95-pwq8.json b/advisories/unreviewed/2025/05/GHSA-9gm2-8g95-pwq8/GHSA-9gm2-8g95-pwq8.json
new file mode 100644
index 00000000000..10267b4748f
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-9gm2-8g95-pwq8/GHSA-9gm2-8g95-pwq8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9gm2-8g95-pwq8",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47550"
+ ],
+ "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio allows Upload a Web Shell to a Web Server. This issue affects Instantio: from n/a through 3.3.16.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47550"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/instantio/vulnerability/wordpress-instantio-3-3-16-arbitrary-file-upload-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-434"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-9gqv-fg2w-3mm9/GHSA-9gqv-fg2w-3mm9.json b/advisories/unreviewed/2025/05/GHSA-9gqv-fg2w-3mm9/GHSA-9gqv-fg2w-3mm9.json
new file mode 100644
index 00000000000..007fdae75c8
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-9gqv-fg2w-3mm9/GHSA-9gqv-fg2w-3mm9.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9gqv-fg2w-3mm9",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47490"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail allows SQL Injection. This issue affects Ultimate WP Mail: from n/a through 1.3.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47490"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ultimate-wp-mail/vulnerability/wordpress-ultimate-wp-mail-1-3-4-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-9hv9-87gp-7pw8/GHSA-9hv9-87gp-7pw8.json b/advisories/unreviewed/2025/05/GHSA-9hv9-87gp-7pw8/GHSA-9hv9-87gp-7pw8.json
new file mode 100644
index 00000000000..c48bc9bee17
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-9hv9-87gp-7pw8/GHSA-9hv9-87gp-7pw8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9hv9-87gp-7pw8",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47489"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in markkinchin Beds24 Online Booking allows Stored XSS. This issue affects Beds24 Online Booking: from n/a through 2.0.29.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47489"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/beds24-online-booking/vulnerability/wordpress-beds24-online-booking-2-0-29-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-9jjh-93j4-23f2/GHSA-9jjh-93j4-23f2.json b/advisories/unreviewed/2025/05/GHSA-9jjh-93j4-23f2/GHSA-9jjh-93j4-23f2.json
index bce77747e31..8c2c6418e23 100644
--- a/advisories/unreviewed/2025/05/GHSA-9jjh-93j4-23f2/GHSA-9jjh-93j4-23f2.json
+++ b/advisories/unreviewed/2025/05/GHSA-9jjh-93j4-23f2/GHSA-9jjh-93j4-23f2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jjh-93j4-23f2",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49876"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix general-protection-fault in ieee80211_subif_start_xmit()\n\nWhen device is running and the interface status is changed, the gpf issue\nis triggered. The problem triggering process is as follows:\nThread A: Thread B\nieee80211_runtime_change_iftype() process_one_work()\n ... ...\n ieee80211_do_stop() ...\n ... ...\n sdata->bss = NULL ...\n ... ieee80211_subif_start_xmit()\n ieee80211_multicast_to_unicast\n //!sdata->bss->multicast_to_unicast\n cause gpf issue\n\nWhen the interface status is changed, the sending queue continues to send\npackets. After the bss is set to NULL, the bss is accessed. As a result,\nthis causes a general-protection-fault issue.\n\nThe following is the stack information:\ngeneral protection fault, probably for non-canonical address\n0xdffffc000000002f: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x0000000000000178-0x000000000000017f]\nWorkqueue: mld mld_ifc_work\nRIP: 0010:ieee80211_subif_start_xmit+0x25b/0x1310\nCall Trace:\n\ndev_hard_start_xmit+0x1be/0x990\n__dev_queue_xmit+0x2c9a/0x3b60\nip6_finish_output2+0xf92/0x1520\nip6_finish_output+0x6af/0x11e0\nip6_output+0x1ed/0x540\nmld_sendpack+0xa09/0xe70\nmld_ifc_work+0x71c/0xdb0\nprocess_one_work+0x9bf/0x1710\nworker_thread+0x665/0x1080\nkthread+0x2e4/0x3a0\nret_from_fork+0x1f/0x30\n",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:12Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-c3wj-ccw7-8f86/GHSA-c3wj-ccw7-8f86.json b/advisories/unreviewed/2025/05/GHSA-c3wj-ccw7-8f86/GHSA-c3wj-ccw7-8f86.json
new file mode 100644
index 00000000000..b50b527646b
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-c3wj-ccw7-8f86/GHSA-c3wj-ccw7-8f86.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c3wj-ccw7-8f86",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:42Z",
+ "aliases": [
+ "CVE-2025-47441"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Reynolds Progress Bar allows Stored XSS. This issue affects Progress Bar: from n/a through 2.2.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47441"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/progress-bar/vulnerability/wordpress-progress-bar-2-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:58Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-c5ch-hjcg-5vxx/GHSA-c5ch-hjcg-5vxx.json b/advisories/unreviewed/2025/05/GHSA-c5ch-hjcg-5vxx/GHSA-c5ch-hjcg-5vxx.json
new file mode 100644
index 00000000000..21b100cb9f7
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-c5ch-hjcg-5vxx/GHSA-c5ch-hjcg-5vxx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c5ch-hjcg-5vxx",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47625"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in apasionados DoFollow Case by Case allows Stored XSS. This issue affects DoFollow Case by Case: from n/a through 3.5.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47625"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/dofollow-case-by-case/vulnerability/wordpress-dofollow-case-by-case-3-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-c6vf-xrgp-vwvx/GHSA-c6vf-xrgp-vwvx.json b/advisories/unreviewed/2025/05/GHSA-c6vf-xrgp-vwvx/GHSA-c6vf-xrgp-vwvx.json
new file mode 100644
index 00000000000..27013f67ea4
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-c6vf-xrgp-vwvx/GHSA-c6vf-xrgp-vwvx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c6vf-xrgp-vwvx",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47467"
+ ],
+ "details": "Missing Authorization vulnerability in GS Plugins GS Testimonial Slider allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GS Testimonial Slider: from n/a through 3.3.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47467"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gs-testimonial/vulnerability/wordpress-gs-testimonial-slider-3-3-0-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-c7jg-hhpr-v5pq/GHSA-c7jg-hhpr-v5pq.json b/advisories/unreviewed/2025/05/GHSA-c7jg-hhpr-v5pq/GHSA-c7jg-hhpr-v5pq.json
index afa50b8fd0b..2c55e37f8e3 100644
--- a/advisories/unreviewed/2025/05/GHSA-c7jg-hhpr-v5pq/GHSA-c7jg-hhpr-v5pq.json
+++ b/advisories/unreviewed/2025/05/GHSA-c7jg-hhpr-v5pq/GHSA-c7jg-hhpr-v5pq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7jg-hhpr-v5pq",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49869"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix possible crash in bnxt_hwrm_set_coal()\n\nDuring the error recovery sequence, the rtnl_lock is not held for the\nentire duration and some datastructures may be freed during the sequence.\nCheck for the BNXT_STATE_OPEN flag instead of netif_running() to ensure\nthat the device is fully operational before proceeding to reconfigure\nthe coalescing settings.\n\nThis will fix a possible crash like this:\n\nBUG: unable to handle kernel NULL pointer dereference at 0000000000000000\nPGD 0 P4D 0\nOops: 0000 [#1] SMP NOPTI\nCPU: 10 PID: 181276 Comm: ethtool Kdump: loaded Tainted: G IOE --------- - - 4.18.0-348.el8.x86_64 #1\nHardware name: Dell Inc. PowerEdge R740/0F9N89, BIOS 2.3.10 08/15/2019\nRIP: 0010:bnxt_hwrm_set_coal+0x1fb/0x2a0 [bnxt_en]\nCode: c2 66 83 4e 22 08 66 89 46 1c e8 10 cb 00 00 41 83 c6 01 44 39 b3 68 01 00 00 0f 8e a3 00 00 00 48 8b 93 c8 00 00 00 49 63 c6 <48> 8b 2c c2 48 8b 85 b8 02 00 00 48 85 c0 74 2e 48 8b 74 24 08 f6\nRSP: 0018:ffffb11c8dcaba50 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff8d168a8b0ac0 RCX: 00000000000000c5\nRDX: 0000000000000000 RSI: ffff8d162f72c000 RDI: ffff8d168a8b0b28\nRBP: 0000000000000000 R08: b6e1f68a12e9a7eb R09: 0000000000000000\nR10: 0000000000000001 R11: 0000000000000037 R12: ffff8d168a8b109c\nR13: ffff8d168a8b10aa R14: 0000000000000000 R15: ffffffffc01ac4e0\nFS: 00007f3852e4c740(0000) GS:ffff8d24c0080000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000000 CR3: 000000041b3ee003 CR4: 00000000007706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n ethnl_set_coalesce+0x3ce/0x4c0\n genl_family_rcv_msg_doit.isra.15+0x10f/0x150\n genl_family_rcv_msg+0xb3/0x160\n ? coalesce_fill_reply+0x480/0x480\n genl_rcv_msg+0x47/0x90\n ? genl_family_rcv_msg+0x160/0x160\n netlink_rcv_skb+0x4c/0x120\n genl_rcv+0x24/0x40\n netlink_unicast+0x196/0x230\n netlink_sendmsg+0x204/0x3d0\n sock_sendmsg+0x4c/0x50\n __sys_sendto+0xee/0x160\n ? syscall_trace_enter+0x1d3/0x2c0\n ? __audit_syscall_exit+0x249/0x2a0\n __x64_sys_sendto+0x24/0x30\n do_syscall_64+0x5b/0x1a0\n entry_SYSCALL_64_after_hwframe+0x65/0xca\nRIP: 0033:0x7f38524163bb",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:11Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-c8c6-w3c6-hrfr/GHSA-c8c6-w3c6-hrfr.json b/advisories/unreviewed/2025/05/GHSA-c8c6-w3c6-hrfr/GHSA-c8c6-w3c6-hrfr.json
new file mode 100644
index 00000000000..59e33d3b067
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-c8c6-w3c6-hrfr/GHSA-c8c6-w3c6-hrfr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c8c6-w3c6-hrfr",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47621"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meks Meks Flexible Shortcodes allows Stored XSS. This issue affects Meks Flexible Shortcodes: from n/a through 1.3.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47621"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/meks-flexible-shortcodes/vulnerability/wordpress-meks-flexible-shortcodes-1-3-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-c8r4-j2q4-mjgj/GHSA-c8r4-j2q4-mjgj.json b/advisories/unreviewed/2025/05/GHSA-c8r4-j2q4-mjgj/GHSA-c8r4-j2q4-mjgj.json
index fad2c5b5fec..1cc088afd04 100644
--- a/advisories/unreviewed/2025/05/GHSA-c8r4-j2q4-mjgj/GHSA-c8r4-j2q4-mjgj.json
+++ b/advisories/unreviewed/2025/05/GHSA-c8r4-j2q4-mjgj/GHSA-c8r4-j2q4-mjgj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8r4-j2q4-mjgj",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49875"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpftool: Fix NULL pointer dereference when pin {PROG, MAP, LINK} without FILE\n\nWhen using bpftool to pin {PROG, MAP, LINK} without FILE,\nsegmentation fault will occur. The reson is that the lack\nof FILE will cause strlen to trigger NULL pointer dereference.\nThe corresponding stacktrace is shown below:\n\ndo_pin\n do_pin_any\n do_pin_fd\n mount_bpffs_for_pin\n strlen(name) <- NULL pointer dereference\n\nFix it by adding validation to the common process.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:12Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-cfq2-3x3p-fqxp/GHSA-cfq2-3x3p-fqxp.json b/advisories/unreviewed/2025/05/GHSA-cfq2-3x3p-fqxp/GHSA-cfq2-3x3p-fqxp.json
index 4607a12cf19..af572dfaded 100644
--- a/advisories/unreviewed/2025/05/GHSA-cfq2-3x3p-fqxp/GHSA-cfq2-3x3p-fqxp.json
+++ b/advisories/unreviewed/2025/05/GHSA-cfq2-3x3p-fqxp/GHSA-cfq2-3x3p-fqxp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cfq2-3x3p-fqxp",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:52Z",
"aliases": [
"CVE-2022-49904"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet, neigh: Fix null-ptr-deref in neigh_table_clear()\n\nWhen IPv6 module gets initialized but hits an error in the middle,\nkenel panic with:\n\nKASAN: null-ptr-deref in range [0x0000000000000598-0x000000000000059f]\nCPU: 1 PID: 361 Comm: insmod\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996)\nRIP: 0010:__neigh_ifdown.isra.0+0x24b/0x370\nRSP: 0018:ffff888012677908 EFLAGS: 00000202\n...\nCall Trace:\n \n neigh_table_clear+0x94/0x2d0\n ndisc_cleanup+0x27/0x40 [ipv6]\n inet6_init+0x21c/0x2cb [ipv6]\n do_one_initcall+0xd3/0x4d0\n do_init_module+0x1ae/0x670\n...\nKernel panic - not syncing: Fatal exception\n\nWhen ipv6 initialization fails, it will try to cleanup and calls:\n\nneigh_table_clear()\n neigh_ifdown(tbl, NULL)\n pneigh_queue_purge(&tbl->proxy_queue, dev_net(dev == NULL))\n # dev_net(NULL) triggers null-ptr-deref.\n\nFix it by passing NULL to pneigh_queue_purge() in neigh_ifdown() if dev\nis NULL, to make kernel not panic immediately.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:15Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-cg7j-h47w-rp3m/GHSA-cg7j-h47w-rp3m.json b/advisories/unreviewed/2025/05/GHSA-cg7j-h47w-rp3m/GHSA-cg7j-h47w-rp3m.json
new file mode 100644
index 00000000000..6c30e858bb4
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-cg7j-h47w-rp3m/GHSA-cg7j-h47w-rp3m.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cg7j-h47w-rp3m",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47455"
+ ],
+ "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and Salesforce allows Phishing. This issue affects Integration for WooCommerce and Salesforce: from n/a through 1.7.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47455"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/woo-salesforce-plugin-crm-perks/vulnerability/wordpress-integration-for-woocommerce-and-salesforce-1-7-5-open-redirection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-601"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:59Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-cgcc-8vq7-798x/GHSA-cgcc-8vq7-798x.json b/advisories/unreviewed/2025/05/GHSA-cgcc-8vq7-798x/GHSA-cgcc-8vq7-798x.json
new file mode 100644
index 00000000000..da59acb185d
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-cgcc-8vq7-798x/GHSA-cgcc-8vq7-798x.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cgcc-8vq7-798x",
+ "modified": "2025-05-07T15:31:49Z",
+ "published": "2025-05-07T15:31:49Z",
+ "aliases": [
+ "CVE-2025-47692"
+ ],
+ "details": "Missing Authorization vulnerability in contentstudio ContentStudio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ContentStudio: from n/a through 1.3.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47692"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/contentstudio/vulnerability/wordpress-contentstudio-1-3-3-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-cpjv-5wwh-mwg5/GHSA-cpjv-5wwh-mwg5.json b/advisories/unreviewed/2025/05/GHSA-cpjv-5wwh-mwg5/GHSA-cpjv-5wwh-mwg5.json
new file mode 100644
index 00000000000..2e7fa1e431e
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-cpjv-5wwh-mwg5/GHSA-cpjv-5wwh-mwg5.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cpjv-5wwh-mwg5",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47548"
+ ],
+ "details": "Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress allows Server Side Request Forgery. This issue affects Wbcom Designs - Activity Link Preview For BuddyPress: from n/a through 1.4.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47548"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/activity-link-preview-for-buddypress/vulnerability/wordpress-wbcom-designs-activity-link-preview-for-buddypress-1-4-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-cwv3-f63m-6h8c/GHSA-cwv3-f63m-6h8c.json b/advisories/unreviewed/2025/05/GHSA-cwv3-f63m-6h8c/GHSA-cwv3-f63m-6h8c.json
new file mode 100644
index 00000000000..69c242c09b7
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-cwv3-f63m-6h8c/GHSA-cwv3-f63m-6h8c.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cwv3-f63m-6h8c",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:42Z",
+ "aliases": [
+ "CVE-2025-47439"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor allows PHP Local File Inclusion. This issue affects Download Monitor: from n/a through 5.0.22.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47439"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/download-monitor/vulnerability/wordpress-download-monitor-5-0-22-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:57Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-cx66-mw68-mp8j/GHSA-cx66-mw68-mp8j.json b/advisories/unreviewed/2025/05/GHSA-cx66-mw68-mp8j/GHSA-cx66-mw68-mp8j.json
new file mode 100644
index 00000000000..d9b2c5c8b34
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-cx66-mw68-mp8j/GHSA-cx66-mw68-mp8j.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cx66-mw68-mp8j",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47508"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ruben Garcia GamiPress allows PHP Local File Inclusion. This issue affects GamiPress: from n/a through 7.3.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47508"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gamipress/vulnerability/wordpress-gamipress-7-3-7-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-f24g-q9m8-ph2r/GHSA-f24g-q9m8-ph2r.json b/advisories/unreviewed/2025/05/GHSA-f24g-q9m8-ph2r/GHSA-f24g-q9m8-ph2r.json
new file mode 100644
index 00000000000..3f03f48f443
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-f24g-q9m8-ph2r/GHSA-f24g-q9m8-ph2r.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f24g-q9m8-ph2r",
+ "modified": "2025-05-07T15:31:49Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47691"
+ ],
+ "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member allows Code Injection. This issue affects Ultimate Member: from n/a through 2.10.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47691"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ultimate-member/vulnerability/wordpress-ultimate-member-plugin-2-10-3-arbitrary-function-call-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-94"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-f62m-xcf9-8m88/GHSA-f62m-xcf9-8m88.json b/advisories/unreviewed/2025/05/GHSA-f62m-xcf9-8m88/GHSA-f62m-xcf9-8m88.json
new file mode 100644
index 00000000000..ec68dbd1870
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-f62m-xcf9-8m88/GHSA-f62m-xcf9-8m88.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f62m-xcf9-8m88",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47684"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Smaily Smaily for WP allows Cross Site Request Forgery. This issue affects Smaily for WP: from n/a through 3.1.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47684"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/smaily-for-wp/vulnerability/wordpress-smaily-for-wp-3-1-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-fcg8-r56h-vmgr/GHSA-fcg8-r56h-vmgr.json b/advisories/unreviewed/2025/05/GHSA-fcg8-r56h-vmgr/GHSA-fcg8-r56h-vmgr.json
new file mode 100644
index 00000000000..b6cd3764433
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-fcg8-r56h-vmgr/GHSA-fcg8-r56h-vmgr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fcg8-r56h-vmgr",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47465"
+ ],
+ "details": "Missing Authorization vulnerability in CreativeThemes Blocksy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Blocksy: from n/a through 2.0.97.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47465"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/theme/blocksy/vulnerability/wordpress-blocksy-2-0-97-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-fpwm-r92q-hvjc/GHSA-fpwm-r92q-hvjc.json b/advisories/unreviewed/2025/05/GHSA-fpwm-r92q-hvjc/GHSA-fpwm-r92q-hvjc.json
index 2312508fcd5..b451b87bb70 100644
--- a/advisories/unreviewed/2025/05/GHSA-fpwm-r92q-hvjc/GHSA-fpwm-r92q-hvjc.json
+++ b/advisories/unreviewed/2025/05/GHSA-fpwm-r92q-hvjc/GHSA-fpwm-r92q-hvjc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fpwm-r92q-hvjc",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49863"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: af_can: fix NULL pointer dereference in can_rx_register()\n\nIt causes NULL pointer dereference when testing as following:\n(a) use syscall(__NR_socket, 0x10ul, 3ul, 0) to create netlink socket.\n(b) use syscall(__NR_sendmsg, ...) to create bond link device and vxcan\n link device, and bind vxcan device to bond device (can also use\n ifenslave command to bind vxcan device to bond device).\n(c) use syscall(__NR_socket, 0x1dul, 3ul, 1) to create CAN socket.\n(d) use syscall(__NR_bind, ...) to bind the bond device to CAN socket.\n\nThe bond device invokes the can-raw protocol registration interface to\nreceive CAN packets. However, ml_priv is not allocated to the dev,\ndev_rcv_lists is assigned to NULL in can_rx_register(). In this case,\nit will occur the NULL pointer dereference issue.\n\nThe following is the stack information:\nBUG: kernel NULL pointer dereference, address: 0000000000000008\nPGD 122a4067 P4D 122a4067 PUD 1223c067 PMD 0\nOops: 0000 [#1] PREEMPT SMP\nRIP: 0010:can_rx_register+0x12d/0x1e0\nCall Trace:\n\nraw_enable_filters+0x8d/0x120\nraw_enable_allfilters+0x3b/0x130\nraw_bind+0x118/0x4f0\n__sys_bind+0x163/0x1a0\n__x64_sys_bind+0x1e/0x30\ndo_syscall_64+0x35/0x80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\n",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:11Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-fvgh-q297-77rj/GHSA-fvgh-q297-77rj.json b/advisories/unreviewed/2025/05/GHSA-fvgh-q297-77rj/GHSA-fvgh-q297-77rj.json
new file mode 100644
index 00000000000..67f552c8ac0
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-fvgh-q297-77rj/GHSA-fvgh-q297-77rj.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fvgh-q297-77rj",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47476"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Cost Calculator for Elementor allows DOM-Based XSS. This issue affects Cost Calculator for Elementor: from n/a through 1.3.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47476"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/cost-calculator-for-elementor/vulnerability/wordpress-cost-calculator-for-elementor-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-fw2p-r2v5-6jjq/GHSA-fw2p-r2v5-6jjq.json b/advisories/unreviewed/2025/05/GHSA-fw2p-r2v5-6jjq/GHSA-fw2p-r2v5-6jjq.json
index 1f15204aab0..0c9b524e065 100644
--- a/advisories/unreviewed/2025/05/GHSA-fw2p-r2v5-6jjq/GHSA-fw2p-r2v5-6jjq.json
+++ b/advisories/unreviewed/2025/05/GHSA-fw2p-r2v5-6jjq/GHSA-fw2p-r2v5-6jjq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fw2p-r2v5-6jjq",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49881"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: fix memory leak in query_regdb_file()\n\nIn the function query_regdb_file() the alpha2 parameter is duplicated\nusing kmemdup() and subsequently freed in regdb_fw_cb(). However,\nrequest_firmware_nowait() can fail without calling regdb_fw_cb() and\nthus leak memory.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:13Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-fwgj-hxqv-88r6/GHSA-fwgj-hxqv-88r6.json b/advisories/unreviewed/2025/05/GHSA-fwgj-hxqv-88r6/GHSA-fwgj-hxqv-88r6.json
new file mode 100644
index 00000000000..3440ea5aade
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-fwgj-hxqv-88r6/GHSA-fwgj-hxqv-88r6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fwgj-hxqv-88r6",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47677"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery allows Stored XSS. This issue affects Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery: from n/a through 2.7.7.25.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47677"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gt3-photo-video-gallery/vulnerability/wordpress-photo-gallery-gt3-image-gallery-gutenberg-block-gallery-2-7-7-25-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-g3m4-2wr6-2q64/GHSA-g3m4-2wr6-2q64.json b/advisories/unreviewed/2025/05/GHSA-g3m4-2wr6-2q64/GHSA-g3m4-2wr6-2q64.json
new file mode 100644
index 00000000000..a35c0b5d031
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-g3m4-2wr6-2q64/GHSA-g3m4-2wr6-2q64.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g3m4-2wr6-2q64",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2025-2775"
+ ],
+ "details": "SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2775"
+ },
+ {
+ "type": "WEB",
+ "url": "https://documentation.sysaid.com/docs/24-40-60"
+ },
+ {
+ "type": "WEB",
+ "url": "https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-611"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:57Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-g77v-vvxx-rcj7/GHSA-g77v-vvxx-rcj7.json b/advisories/unreviewed/2025/05/GHSA-g77v-vvxx-rcj7/GHSA-g77v-vvxx-rcj7.json
index 19ce67da240..48f3e03525d 100644
--- a/advisories/unreviewed/2025/05/GHSA-g77v-vvxx-rcj7/GHSA-g77v-vvxx-rcj7.json
+++ b/advisories/unreviewed/2025/05/GHSA-g77v-vvxx-rcj7/GHSA-g77v-vvxx-rcj7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g77v-vvxx-rcj7",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:28Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49930"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix NULL pointer problem in free_mr_init()\n\nLock grab occurs in a concurrent scenario, resulting in stepping on a NULL\npointer. It should be init mutex_init() first before use the lock.\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Call trace:\n __mutex_lock.constprop.0+0xd0/0x5c0\n __mutex_lock_slowpath+0x1c/0x2c\n mutex_lock+0x44/0x50\n free_mr_send_cmd_to_hw+0x7c/0x1c0 [hns_roce_hw_v2]\n hns_roce_v2_dereg_mr+0x30/0x40 [hns_roce_hw_v2]\n hns_roce_dereg_mr+0x4c/0x130 [hns_roce_hw_v2]\n ib_dereg_mr_user+0x54/0x124\n uverbs_free_mr+0x24/0x30\n destroy_hw_idr_uobject+0x38/0x74\n uverbs_destroy_uobject+0x48/0x1c4\n uobj_destroy+0x74/0xcc\n ib_uverbs_cmd_verbs+0x368/0xbb0\n ib_uverbs_ioctl+0xec/0x1a4\n __arm64_sys_ioctl+0xb4/0x100\n invoke_syscall+0x50/0x120\n el0_svc_common.constprop.0+0x58/0x190\n do_el0_svc+0x30/0x90\n el0_svc+0x2c/0xb4\n el0t_64_sync_handler+0x1a4/0x1b0\n el0t_64_sync+0x19c/0x1a0",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:18Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-ggfc-mrvr-g693/GHSA-ggfc-mrvr-g693.json b/advisories/unreviewed/2025/05/GHSA-ggfc-mrvr-g693/GHSA-ggfc-mrvr-g693.json
new file mode 100644
index 00000000000..cc72e6ebfb1
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-ggfc-mrvr-g693/GHSA-ggfc-mrvr-g693.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-ggfc-mrvr-g693",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47633"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Awin Awin – Advertiser Tracking for WooCommerce allows Cross Site Request Forgery. This issue affects Awin – Advertiser Tracking for WooCommerce: from n/a through 2.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47633"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/awin-advertiser-tracking/vulnerability/wordpress-awin-advertiser-tracking-for-woocommerce-plugin-2-0-0-csrf-to-product-feed-regeneration-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-gh35-g2f9-cw89/GHSA-gh35-g2f9-cw89.json b/advisories/unreviewed/2025/05/GHSA-gh35-g2f9-cw89/GHSA-gh35-g2f9-cw89.json
new file mode 100644
index 00000000000..898440f45f3
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-gh35-g2f9-cw89/GHSA-gh35-g2f9-cw89.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gh35-g2f9-cw89",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47460"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TrackShip TrackShip for WooCommerce allows SQL Injection. This issue affects TrackShip for WooCommerce: from n/a through 1.9.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47460"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/trackship-for-woocommerce/vulnerability/wordpress-trackship-for-woocommerce-1-9-1-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-ghrp-qr8h-p76p/GHSA-ghrp-qr8h-p76p.json b/advisories/unreviewed/2025/05/GHSA-ghrp-qr8h-p76p/GHSA-ghrp-qr8h-p76p.json
new file mode 100644
index 00000000000..eb2917650d6
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-ghrp-qr8h-p76p/GHSA-ghrp-qr8h-p76p.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-ghrp-qr8h-p76p",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47665"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 | Splash Screen allows Stored XSS. This issue affects N360 | Splash Screen: from n/a through 1.0.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47665"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/n360-splash-screen/vulnerability/wordpress-n360-splash-screen-1-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-gjcg-8q5f-6j48/GHSA-gjcg-8q5f-6j48.json b/advisories/unreviewed/2025/05/GHSA-gjcg-8q5f-6j48/GHSA-gjcg-8q5f-6j48.json
new file mode 100644
index 00000000000..ceb60c94083
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-gjcg-8q5f-6j48/GHSA-gjcg-8q5f-6j48.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gjcg-8q5f-6j48",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47605"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AppJetty WP jQuery DataTable allows Stored XSS. This issue affects WP jQuery DataTable: from n/a through 4.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47605"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-jquery-datatable/vulnerability/wordpress-wp-jquery-datatable-4-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-gjh2-vjq2-jqwc/GHSA-gjh2-vjq2-jqwc.json b/advisories/unreviewed/2025/05/GHSA-gjh2-vjq2-jqwc/GHSA-gjh2-vjq2-jqwc.json
index b2452f4ada0..798d80ac722 100644
--- a/advisories/unreviewed/2025/05/GHSA-gjh2-vjq2-jqwc/GHSA-gjh2-vjq2-jqwc.json
+++ b/advisories/unreviewed/2025/05/GHSA-gjh2-vjq2-jqwc/GHSA-gjh2-vjq2-jqwc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjh2-vjq2-jqwc",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:27Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49923"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nxp-nci: Fix potential memory leak in nxp_nci_send()\n\nnxp_nci_send() will call nxp_nci_i2c_write(), and only free skb when\nnxp_nci_i2c_write() failed. However, even if the nxp_nci_i2c_write()\nrun succeeds, the skb will not be freed in nxp_nci_i2c_write(). As the\nresult, the skb will memleak. nxp_nci_send() should also free the skb\nwhen nxp_nci_i2c_write() succeeds.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:17Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-gp22-5fgh-q68v/GHSA-gp22-5fgh-q68v.json b/advisories/unreviewed/2025/05/GHSA-gp22-5fgh-q68v/GHSA-gp22-5fgh-q68v.json
index a546716c3be..789c5b4684b 100644
--- a/advisories/unreviewed/2025/05/GHSA-gp22-5fgh-q68v/GHSA-gp22-5fgh-q68v.json
+++ b/advisories/unreviewed/2025/05/GHSA-gp22-5fgh-q68v/GHSA-gp22-5fgh-q68v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gp22-5fgh-q68v",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:27Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49924"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: fdp: Fix potential memory leak in fdp_nci_send()\n\nfdp_nci_send() will call fdp_nci_i2c_write that will not free skb in\nthe function. As a result, when fdp_nci_i2c_write() finished, the skb\nwill memleak. fdp_nci_send() should free skb after fdp_nci_i2c_write()\nfinished.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:18Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-gxxw-w6f5-mwh6/GHSA-gxxw-w6f5-mwh6.json b/advisories/unreviewed/2025/05/GHSA-gxxw-w6f5-mwh6/GHSA-gxxw-w6f5-mwh6.json
new file mode 100644
index 00000000000..e3c9a7573cc
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-gxxw-w6f5-mwh6/GHSA-gxxw-w6f5-mwh6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gxxw-w6f5-mwh6",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47538"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce allows SQL Injection. This issue affects Cart tracking for WooCommerce: from n/a through 1.0.17.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47538"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/cart-tracking-for-woocommerce/vulnerability/wordpress-cart-tracking-for-woocommerce-1-0-17-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-h77r-2fcv-4h5w/GHSA-h77r-2fcv-4h5w.json b/advisories/unreviewed/2025/05/GHSA-h77r-2fcv-4h5w/GHSA-h77r-2fcv-4h5w.json
new file mode 100644
index 00000000000..d1a81278687
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-h77r-2fcv-4h5w/GHSA-h77r-2fcv-4h5w.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-h77r-2fcv-4h5w",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47668"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cookiecode CookieCode allows Stored XSS. This issue affects CookieCode: from n/a through 2.4.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47668"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/cookiecode/vulnerability/wordpress-cookiecode-2-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-hcjv-982c-5f29/GHSA-hcjv-982c-5f29.json b/advisories/unreviewed/2025/05/GHSA-hcjv-982c-5f29/GHSA-hcjv-982c-5f29.json
new file mode 100644
index 00000000000..6cb2df7eef2
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-hcjv-982c-5f29/GHSA-hcjv-982c-5f29.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hcjv-982c-5f29",
+ "modified": "2025-05-07T15:31:41Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2025-29448"
+ ],
+ "details": "A business logic vulnerability in Easy Appointments v1.5.1 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29448"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Abdullah4eb/CVE-2025-29448"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:57Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-hfcv-5vc2-2j5f/GHSA-hfcv-5vc2-2j5f.json b/advisories/unreviewed/2025/05/GHSA-hfcv-5vc2-2j5f/GHSA-hfcv-5vc2-2j5f.json
new file mode 100644
index 00000000000..df9707a516a
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-hfcv-5vc2-2j5f/GHSA-hfcv-5vc2-2j5f.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hfcv-5vc2-2j5f",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47520"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Charitable allows Stored XSS. This issue affects Charitable: from n/a through 1.8.5.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47520"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/charitable/vulnerability/wordpress-charitable-1-8-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-hfq6-gq9r-7wx7/GHSA-hfq6-gq9r-7wx7.json b/advisories/unreviewed/2025/05/GHSA-hfq6-gq9r-7wx7/GHSA-hfq6-gq9r-7wx7.json
new file mode 100644
index 00000000000..700ad0449ab
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-hfq6-gq9r-7wx7/GHSA-hfq6-gq9r-7wx7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hfq6-gq9r-7wx7",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47469"
+ ],
+ "details": "Missing Authorization vulnerability in slui Media Hygiene allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Media Hygiene: from n/a through 4.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47469"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/media-hygiene/vulnerability/wordpress-media-hygiene-4-0-0-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-hpf7-wq23-7pvr/GHSA-hpf7-wq23-7pvr.json b/advisories/unreviewed/2025/05/GHSA-hpf7-wq23-7pvr/GHSA-hpf7-wq23-7pvr.json
index e0cc220b6b0..bafd3e9198e 100644
--- a/advisories/unreviewed/2025/05/GHSA-hpf7-wq23-7pvr/GHSA-hpf7-wq23-7pvr.json
+++ b/advisories/unreviewed/2025/05/GHSA-hpf7-wq23-7pvr/GHSA-hpf7-wq23-7pvr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hpf7-wq23-7pvr",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49860"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: ti: k3-udma-glue: fix memory leak when register device fail\n\nIf device_register() fails, it should call put_device() to give\nup reference, the name allocated in dev_set_name() can be freed\nin callback function kobject_cleanup().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:09Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-hphg-q3xv-rqhp/GHSA-hphg-q3xv-rqhp.json b/advisories/unreviewed/2025/05/GHSA-hphg-q3xv-rqhp/GHSA-hphg-q3xv-rqhp.json
new file mode 100644
index 00000000000..32420acce00
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-hphg-q3xv-rqhp/GHSA-hphg-q3xv-rqhp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hphg-q3xv-rqhp",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47612"
+ ],
+ "details": "Missing Authorization vulnerability in flowdee ClickWhale allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ClickWhale: from n/a through 2.4.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47612"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/clickwhale/vulnerability/wordpress-clickwhale-2-4-6-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-hpvx-8hrq-6wxv/GHSA-hpvx-8hrq-6wxv.json b/advisories/unreviewed/2025/05/GHSA-hpvx-8hrq-6wxv/GHSA-hpvx-8hrq-6wxv.json
new file mode 100644
index 00000000000..ddc75e44bfd
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-hpvx-8hrq-6wxv/GHSA-hpvx-8hrq-6wxv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hpvx-8hrq-6wxv",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47491"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget allows Cross Site Request Forgery. This issue affects Contact Form Widget: from n/a through 1.4.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47491"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/new-contact-form-widget/vulnerability/wordpress-contact-form-widget-1-4-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-hvrh-gfrr-fgc9/GHSA-hvrh-gfrr-fgc9.json b/advisories/unreviewed/2025/05/GHSA-hvrh-gfrr-fgc9/GHSA-hvrh-gfrr-fgc9.json
new file mode 100644
index 00000000000..f2e1e8d2bfc
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-hvrh-gfrr-fgc9/GHSA-hvrh-gfrr-fgc9.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hvrh-gfrr-fgc9",
+ "modified": "2025-05-07T15:31:41Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2025-2776"
+ ],
+ "details": "SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2776"
+ },
+ {
+ "type": "WEB",
+ "url": "https://documentation.sysaid.com/docs/24-40-60"
+ },
+ {
+ "type": "WEB",
+ "url": "https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-611"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:57Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-hxv5-fpm3-vhqh/GHSA-hxv5-fpm3-vhqh.json b/advisories/unreviewed/2025/05/GHSA-hxv5-fpm3-vhqh/GHSA-hxv5-fpm3-vhqh.json
new file mode 100644
index 00000000000..a794ad708af
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-hxv5-fpm3-vhqh/GHSA-hxv5-fpm3-vhqh.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hxv5-fpm3-vhqh",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2025-2777"
+ ],
+ "details": "SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2777"
+ },
+ {
+ "type": "WEB",
+ "url": "https://documentation.sysaid.com/docs/24-40-60"
+ },
+ {
+ "type": "WEB",
+ "url": "https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-611"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:57Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-j23p-pwm3-pw32/GHSA-j23p-pwm3-pw32.json b/advisories/unreviewed/2025/05/GHSA-j23p-pwm3-pw32/GHSA-j23p-pwm3-pw32.json
new file mode 100644
index 00000000000..f773c4baa85
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-j23p-pwm3-pw32/GHSA-j23p-pwm3-pw32.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j23p-pwm3-pw32",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47454"
+ ],
+ "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Dynamics CRM allows Phishing. This issue affects WP Gravity Forms Dynamics CRM: from n/a through 1.1.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47454"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gf-dynamics-crm/vulnerability/wordpress-wp-gravity-forms-dynamics-crm-1-1-4-open-redirection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-601"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:59Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-j3q9-hhvp-mqg6/GHSA-j3q9-hhvp-mqg6.json b/advisories/unreviewed/2025/05/GHSA-j3q9-hhvp-mqg6/GHSA-j3q9-hhvp-mqg6.json
new file mode 100644
index 00000000000..1230480484e
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-j3q9-hhvp-mqg6/GHSA-j3q9-hhvp-mqg6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j3q9-hhvp-mqg6",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47486"
+ ],
+ "details": "Missing Authorization vulnerability in CyberChimps Gutenberg & Elementor Templates Importer For Responsive allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gutenberg & Elementor Templates Importer For Responsive: from n/a through 3.1.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47486"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/responsive-add-ons/vulnerability/wordpress-gutenberg-elementor-templates-importer-for-responsive-3-1-9-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-j8vr-xhj5-c3vw/GHSA-j8vr-xhj5-c3vw.json b/advisories/unreviewed/2025/05/GHSA-j8vr-xhj5-c3vw/GHSA-j8vr-xhj5-c3vw.json
new file mode 100644
index 00000000000..b94626878f8
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-j8vr-xhj5-c3vw/GHSA-j8vr-xhj5-c3vw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j8vr-xhj5-c3vw",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47544"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce allows Blind SQL Injection. This issue affects Dynamic Pricing With Discount Rules for WooCommerce: from n/a through 4.5.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47544"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/aco-woo-dynamic-pricing/vulnerability/wordpress-dynamic-pricing-with-discount-rules-for-woocommerce-4-5-8-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-jfg5-8678-gx36/GHSA-jfg5-8678-gx36.json b/advisories/unreviewed/2025/05/GHSA-jfg5-8678-gx36/GHSA-jfg5-8678-gx36.json
new file mode 100644
index 00000000000..61190c99510
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-jfg5-8678-gx36/GHSA-jfg5-8678-gx36.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jfg5-8678-gx36",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47636"
+ ],
+ "details": "Path Traversal vulnerability in Fernando Briano List category posts allows PHP Local File Inclusion. This issue affects List category posts: from n/a through 0.90.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47636"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/list-category-posts/vulnerability/wordpress-list-category-posts-0-90-3-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-35"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-jfw6-w783-5hhm/GHSA-jfw6-w783-5hhm.json b/advisories/unreviewed/2025/05/GHSA-jfw6-w783-5hhm/GHSA-jfw6-w783-5hhm.json
index 5bbdd45d13a..4140980ed71 100644
--- a/advisories/unreviewed/2025/05/GHSA-jfw6-w783-5hhm/GHSA-jfw6-w783-5hhm.json
+++ b/advisories/unreviewed/2025/05/GHSA-jfw6-w783-5hhm/GHSA-jfw6-w783-5hhm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jfw6-w783-5hhm",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49871"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tun: Fix memory leaks of napi_get_frags\n\nkmemleak reports after running test_progs:\n\nunreferenced object 0xffff8881b1672dc0 (size 232):\n comm \"test_progs\", pid 394388, jiffies 4354712116 (age 841.975s)\n hex dump (first 32 bytes):\n e0 84 d7 a8 81 88 ff ff 80 2c 67 b1 81 88 ff ff .........,g.....\n 00 40 c5 9b 81 88 ff ff 00 00 00 00 00 00 00 00 .@..............\n backtrace:\n [<00000000c8f01748>] napi_skb_cache_get+0xd4/0x150\n [<0000000041c7fc09>] __napi_build_skb+0x15/0x50\n [<00000000431c7079>] __napi_alloc_skb+0x26e/0x540\n [<000000003ecfa30e>] napi_get_frags+0x59/0x140\n [<0000000099b2199e>] tun_get_user+0x183d/0x3bb0 [tun]\n [<000000008a5adef0>] tun_chr_write_iter+0xc0/0x1b1 [tun]\n [<0000000049993ff4>] do_iter_readv_writev+0x19f/0x320\n [<000000008f338ea2>] do_iter_write+0x135/0x630\n [<000000008a3377a4>] vfs_writev+0x12e/0x440\n [<00000000a6b5639a>] do_writev+0x104/0x280\n [<00000000ccf065d8>] do_syscall_64+0x3b/0x90\n [<00000000d776e329>] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe issue occurs in the following scenarios:\ntun_get_user()\n napi_gro_frags()\n napi_frags_finish()\n case GRO_NORMAL:\n gro_normal_one()\n list_add_tail(&skb->list, &napi->rx_list);\n <-- While napi->rx_count < READ_ONCE(gro_normal_batch),\n <-- gro_normal_list() is not called, napi->rx_list is not empty\n <-- not ask to complete the gro work, will cause memory leaks in\n <-- following tun_napi_del()\n...\ntun_napi_del()\n netif_napi_del()\n __netif_napi_del()\n <-- &napi->rx_list is not empty, which caused memory leaks\n\nTo fix, add napi_complete() after napi_gro_frags().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:12Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-jg5q-27fm-xjrh/GHSA-jg5q-27fm-xjrh.json b/advisories/unreviewed/2025/05/GHSA-jg5q-27fm-xjrh/GHSA-jg5q-27fm-xjrh.json
new file mode 100644
index 00000000000..b130cfec82c
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-jg5q-27fm-xjrh/GHSA-jg5q-27fm-xjrh.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jg5q-27fm-xjrh",
+ "modified": "2025-05-07T15:31:49Z",
+ "published": "2025-05-07T15:31:49Z",
+ "aliases": [
+ "CVE-2025-47686"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO allows Stored XSS. This issue affects DELUCKS SEO: from n/a through 2.5.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47686"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/delucks-seo/vulnerability/wordpress-delucks-seo-2-5-9-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-jjg4-p57c-87j3/GHSA-jjg4-p57c-87j3.json b/advisories/unreviewed/2025/05/GHSA-jjg4-p57c-87j3/GHSA-jjg4-p57c-87j3.json
index 5d90c00a4cf..5aa96ad2576 100644
--- a/advisories/unreviewed/2025/05/GHSA-jjg4-p57c-87j3/GHSA-jjg4-p57c-87j3.json
+++ b/advisories/unreviewed/2025/05/GHSA-jjg4-p57c-87j3/GHSA-jjg4-p57c-87j3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jjg4-p57c-87j3",
- "modified": "2025-05-01T15:31:49Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49844"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: dev: fix skb drop check\n\nIn commit a6d190f8c767 (\"can: skb: drop tx skb if in listen only\nmode\") the priv->ctrlmode element is read even on virtual CAN\ninterfaces that do not create the struct can_priv at startup. This\nout-of-bounds read may lead to CAN frame drops for virtual CAN\ninterfaces like vcan and vxcan.\n\nThis patch mainly reverts the original commit and adds a new helper\nfor CAN interface drivers that provide the required information in\nstruct can_priv.\n\n[mkl: patch pch_can, too]",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:07Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-jm2j-x4xc-567m/GHSA-jm2j-x4xc-567m.json b/advisories/unreviewed/2025/05/GHSA-jm2j-x4xc-567m/GHSA-jm2j-x4xc-567m.json
new file mode 100644
index 00000000000..43abb840d43
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-jm2j-x4xc-567m/GHSA-jm2j-x4xc-567m.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jm2j-x4xc-567m",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47504"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Custom Checkout Fields for WooCommerce allows Stored XSS. This issue affects Custom Checkout Fields for WooCommerce: from n/a through 1.8.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47504"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/custom-checkout-fields-for-woocommerce/vulnerability/wordpress-custom-checkout-fields-for-woocommerce-1-8-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-jr2q-36h8-7j24/GHSA-jr2q-36h8-7j24.json b/advisories/unreviewed/2025/05/GHSA-jr2q-36h8-7j24/GHSA-jr2q-36h8-7j24.json
new file mode 100644
index 00000000000..c444e3ee15d
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-jr2q-36h8-7j24/GHSA-jr2q-36h8-7j24.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jr2q-36h8-7j24",
+ "modified": "2025-05-07T15:31:41Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2025-29602"
+ ],
+ "details": "flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29602"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/flatpressblog/flatpress"
+ },
+ {
+ "type": "WEB",
+ "url": "https://harish0x.github.io/blog/CVE-2025-29602"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T14:15:42Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-jrcj-jfvh-q4q9/GHSA-jrcj-jfvh-q4q9.json b/advisories/unreviewed/2025/05/GHSA-jrcj-jfvh-q4q9/GHSA-jrcj-jfvh-q4q9.json
new file mode 100644
index 00000000000..15aa617d898
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-jrcj-jfvh-q4q9/GHSA-jrcj-jfvh-q4q9.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jrcj-jfvh-q4q9",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47649"
+ ],
+ "details": "Path Traversal vulnerability in ilmosys Open Close WooCommerce Store allows PHP Local File Inclusion. This issue affects Open Close WooCommerce Store: from n/a through 4.9.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47649"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/woc-open-close/vulnerability/wordpress-open-close-woocommerce-store-4-9-5-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-35"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-jrg4-c2wj-wpvf/GHSA-jrg4-c2wj-wpvf.json b/advisories/unreviewed/2025/05/GHSA-jrg4-c2wj-wpvf/GHSA-jrg4-c2wj-wpvf.json
new file mode 100644
index 00000000000..6471813e273
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-jrg4-c2wj-wpvf/GHSA-jrg4-c2wj-wpvf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jrg4-c2wj-wpvf",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47604"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Migitation, Inc. Inline Related Posts allows Stored XSS. This issue affects Inline Related Posts: from n/a through 3.8.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47604"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/intelly-related-posts/vulnerability/wordpress-inline-related-posts-3-8-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-jxrv-m7f3-wm3w/GHSA-jxrv-m7f3-wm3w.json b/advisories/unreviewed/2025/05/GHSA-jxrv-m7f3-wm3w/GHSA-jxrv-m7f3-wm3w.json
new file mode 100644
index 00000000000..284a7c26350
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-jxrv-m7f3-wm3w/GHSA-jxrv-m7f3-wm3w.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jxrv-m7f3-wm3w",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47531"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47531"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/xt-facebook-events/vulnerability/wordpress-xt-event-widget-for-social-events-1-1-7-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-m3j7-r27p-7m78/GHSA-m3j7-r27p-7m78.json b/advisories/unreviewed/2025/05/GHSA-m3j7-r27p-7m78/GHSA-m3j7-r27p-7m78.json
index 817982a853e..cc09244fd0c 100644
--- a/advisories/unreviewed/2025/05/GHSA-m3j7-r27p-7m78/GHSA-m3j7-r27p-7m78.json
+++ b/advisories/unreviewed/2025/05/GHSA-m3j7-r27p-7m78/GHSA-m3j7-r27p-7m78.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3j7-r27p-7m78",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49855"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: iosm: fix memory leak in ipc_pcie_read_bios_cfg\n\nipc_pcie_read_bios_cfg() is using the acpi_evaluate_dsm() to\nobtain the wwan power state configuration from BIOS but is\nnot freeing the acpi_object. The acpi_evaluate_dsm() returned\nacpi_object to be freed.\n\nFree the acpi_object after use.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:09Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-m4fq-mxq3-vjm4/GHSA-m4fq-mxq3-vjm4.json b/advisories/unreviewed/2025/05/GHSA-m4fq-mxq3-vjm4/GHSA-m4fq-mxq3-vjm4.json
new file mode 100644
index 00000000000..e079c671b36
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-m4fq-mxq3-vjm4/GHSA-m4fq-mxq3-vjm4.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m4fq-mxq3-vjm4",
+ "modified": "2025-05-07T15:31:41Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2025-29153"
+ ],
+ "details": "SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the Data export, filters functions.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29153"
+ },
+ {
+ "type": "WEB",
+ "url": "https://wellington-almeida.medium.com/poc-sql-391c437c3960"
+ },
+ {
+ "type": "WEB",
+ "url": "https://worzyus.medium.com/391c437c3960"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T14:15:42Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-m5fr-fg72-32gg/GHSA-m5fr-fg72-32gg.json b/advisories/unreviewed/2025/05/GHSA-m5fr-fg72-32gg/GHSA-m5fr-fg72-32gg.json
new file mode 100644
index 00000000000..b591c7122da
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-m5fr-fg72-32gg/GHSA-m5fr-fg72-32gg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m5fr-fg72-32gg",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47456"
+ ],
+ "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zendesk allows Phishing. This issue affects WP Gravity Forms Zendesk: from n/a through 1.1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47456"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gf-zendesk/vulnerability/wordpress-wp-gravity-forms-zendesk-1-1-2-open-redirection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-601"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:59Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-m8v9-m9wg-xv5q/GHSA-m8v9-m9wg-xv5q.json b/advisories/unreviewed/2025/05/GHSA-m8v9-m9wg-xv5q/GHSA-m8v9-m9wg-xv5q.json
new file mode 100644
index 00000000000..6daa8112fd6
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-m8v9-m9wg-xv5q/GHSA-m8v9-m9wg-xv5q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m8v9-m9wg-xv5q",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47462"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ohidul Islam Challan allows Privilege Escalation. This issue affects Challan: from n/a through 3.7.58.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47462"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/webappick-pdf-invoice-for-woocommerce/vulnerability/wordpress-challan-plugin-3-7-58-csrf-to-privilege-escalation-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-m8x7-f64c-28w3/GHSA-m8x7-f64c-28w3.json b/advisories/unreviewed/2025/05/GHSA-m8x7-f64c-28w3/GHSA-m8x7-f64c-28w3.json
index cb4ee3ff4e2..3ed746f1903 100644
--- a/advisories/unreviewed/2025/05/GHSA-m8x7-f64c-28w3/GHSA-m8x7-f64c-28w3.json
+++ b/advisories/unreviewed/2025/05/GHSA-m8x7-f64c-28w3/GHSA-m8x7-f64c-28w3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8x7-f64c-28w3",
- "modified": "2025-05-01T15:31:49Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49850"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix deadlock in nilfs_count_free_blocks()\n\nA semaphore deadlock can occur if nilfs_get_block() detects metadata\ncorruption while locating data blocks and a superblock writeback occurs at\nthe same time:\n\ntask 1 task 2\n------ ------\n* A file operation *\nnilfs_truncate()\n nilfs_get_block()\n down_read(rwsem A) <--\n nilfs_bmap_lookup_contig()\n ... generic_shutdown_super()\n nilfs_put_super()\n * Prepare to write superblock *\n down_write(rwsem B) <--\n nilfs_cleanup_super()\n * Detect b-tree corruption * nilfs_set_log_cursor()\n nilfs_bmap_convert_error() nilfs_count_free_blocks()\n __nilfs_error() down_read(rwsem A) <--\n nilfs_set_error()\n down_write(rwsem B) <--\n\n *** DEADLOCK ***\n\nHere, nilfs_get_block() readlocks rwsem A (= NILFS_MDT(dat_inode)->mi_sem)\nand then calls nilfs_bmap_lookup_contig(), but if it fails due to metadata\ncorruption, __nilfs_error() is called from nilfs_bmap_convert_error()\ninside the lock section.\n\nSince __nilfs_error() calls nilfs_set_error() unless the filesystem is\nread-only and nilfs_set_error() attempts to writelock rwsem B (=\nnilfs->ns_sem) to write back superblock exclusively, hierarchical lock\nacquisition occurs in the order rwsem A -> rwsem B.\n\nNow, if another task starts updating the superblock, it may writelock\nrwsem B during the lock sequence above, and can deadlock trying to\nreadlock rwsem A in nilfs_count_free_blocks().\n\nHowever, there is actually no need to take rwsem A in\nnilfs_count_free_blocks() because it, within the lock section, only reads\na single integer data on a shared struct with\nnilfs_sufile_get_ncleansegs(). This has been the case after commit\naa474a220180 (\"nilfs2: add local variable to cache the number of clean\nsegments\"), that is, even before this bug was introduced.\n\nSo, this resolves the deadlock problem by just not taking the semaphore in\nnilfs_count_free_blocks().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:08Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-mprw-w5ff-xfqg/GHSA-mprw-w5ff-xfqg.json b/advisories/unreviewed/2025/05/GHSA-mprw-w5ff-xfqg/GHSA-mprw-w5ff-xfqg.json
new file mode 100644
index 00000000000..ce58f0b6a88
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-mprw-w5ff-xfqg/GHSA-mprw-w5ff-xfqg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mprw-w5ff-xfqg",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47499"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Blog Stats allows Stored XSS. This issue affects Simple Blog Stats: from n/a through 20250416.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47499"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/simple-blog-stats/vulnerability/wordpress-simple-blog-stats-20250416-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-mqx8-p7fp-jwvw/GHSA-mqx8-p7fp-jwvw.json b/advisories/unreviewed/2025/05/GHSA-mqx8-p7fp-jwvw/GHSA-mqx8-p7fp-jwvw.json
new file mode 100644
index 00000000000..98c67f3ed91
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-mqx8-p7fp-jwvw/GHSA-mqx8-p7fp-jwvw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mqx8-p7fp-jwvw",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47596"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture allows Cross Site Request Forgery. This issue affects Beacon Lead Magnets and Lead Capture: from n/a through 1.5.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47596"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/beacon-by/vulnerability/wordpress-beacon-lead-magnets-and-lead-capture-1-5-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-mx7w-69f4-mg2q/GHSA-mx7w-69f4-mg2q.json b/advisories/unreviewed/2025/05/GHSA-mx7w-69f4-mg2q/GHSA-mx7w-69f4-mg2q.json
index c067c2d699e..d34e97b7528 100644
--- a/advisories/unreviewed/2025/05/GHSA-mx7w-69f4-mg2q/GHSA-mx7w-69f4-mg2q.json
+++ b/advisories/unreviewed/2025/05/GHSA-mx7w-69f4-mg2q/GHSA-mx7w-69f4-mg2q.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mx7w-69f4-mg2q",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:27Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49925"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Fix null-ptr-deref in ib_core_cleanup()\n\nKASAN reported a null-ptr-deref error:\n\n KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\n CPU: 1 PID: 379\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)\n RIP: 0010:destroy_workqueue+0x2f/0x740\n RSP: 0018:ffff888016137df8 EFLAGS: 00000202\n ...\n Call Trace:\n ib_core_cleanup+0xa/0xa1 [ib_core]\n __do_sys_delete_module.constprop.0+0x34f/0x5b0\n do_syscall_64+0x3a/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n RIP: 0033:0x7fa1a0d221b7\n ...\n\nIt is because the fail of roce_gid_mgmt_init() is ignored:\n\n ib_core_init()\n roce_gid_mgmt_init()\n gid_cache_wq = alloc_ordered_workqueue # fail\n ...\n ib_core_cleanup()\n roce_gid_mgmt_cleanup()\n destroy_workqueue(gid_cache_wq)\n # destroy an unallocated wq\n\nFix this by catching the fail of roce_gid_mgmt_init() in ib_core_init().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:18Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-p39f-f66f-x437/GHSA-p39f-f66f-x437.json b/advisories/unreviewed/2025/05/GHSA-p39f-f66f-x437/GHSA-p39f-f66f-x437.json
index 8eacbd64578..7f4c4304af5 100644
--- a/advisories/unreviewed/2025/05/GHSA-p39f-f66f-x437/GHSA-p39f-f66f-x437.json
+++ b/advisories/unreviewed/2025/05/GHSA-p39f-f66f-x437/GHSA-p39f-f66f-x437.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p39f-f66f-x437",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49878"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, verifier: Fix memory leak in array reallocation for stack state\n\nIf an error (NULL) is returned by krealloc(), callers of realloc_array()\nwere setting their allocation pointers to NULL, but on error krealloc()\ndoes not touch the original allocation. This would result in a memory\nresource leak. Instead, free the old allocation on the error handling\npath.\n\nThe memory leak information is as follows as also reported by Zhengchao:\n\n unreferenced object 0xffff888019801800 (size 256):\n comm \"bpf_repo\", pid 6490, jiffies 4294959200 (age 17.170s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000b211474b>] __kmalloc_node_track_caller+0x45/0xc0\n [<0000000086712a0b>] krealloc+0x83/0xd0\n [<00000000139aab02>] realloc_array+0x82/0xe2\n [<00000000b1ca41d1>] grow_stack_state+0xfb/0x186\n [<00000000cd6f36d2>] check_mem_access.cold+0x141/0x1341\n [<0000000081780455>] do_check_common+0x5358/0xb350\n [<0000000015f6b091>] bpf_check.cold+0xc3/0x29d\n [<000000002973c690>] bpf_prog_load+0x13db/0x2240\n [<00000000028d1644>] __sys_bpf+0x1605/0x4ce0\n [<00000000053f29bd>] __x64_sys_bpf+0x75/0xb0\n [<0000000056fedaf5>] do_syscall_64+0x35/0x80\n [<000000002bd58261>] entry_SYSCALL_64_after_hwframe+0x63/0xcd",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:12Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-p45p-8j5c-872r/GHSA-p45p-8j5c-872r.json b/advisories/unreviewed/2025/05/GHSA-p45p-8j5c-872r/GHSA-p45p-8j5c-872r.json
new file mode 100644
index 00000000000..b357f5e788b
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-p45p-8j5c-872r/GHSA-p45p-8j5c-872r.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p45p-8j5c-872r",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47547"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter allows Stored XSS. This issue affects SendPulse Email Marketing Newsletter: from n/a through 2.1.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47547"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/sendpulse-email-marketing-newsletter/vulnerability/wordpress-sendpulse-email-marketing-newsletter-2-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-p59w-r597-mmwf/GHSA-p59w-r597-mmwf.json b/advisories/unreviewed/2025/05/GHSA-p59w-r597-mmwf/GHSA-p59w-r597-mmwf.json
index 919f82be465..edeedf262e2 100644
--- a/advisories/unreviewed/2025/05/GHSA-p59w-r597-mmwf/GHSA-p59w-r597-mmwf.json
+++ b/advisories/unreviewed/2025/05/GHSA-p59w-r597-mmwf/GHSA-p59w-r597-mmwf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p59w-r597-mmwf",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49873"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix wrong reg type conversion in release_reference()\n\nSome helper functions will allocate memory. To avoid memory leaks, the\nverifier requires the eBPF program to release these memories by calling\nthe corresponding helper functions.\n\nWhen a resource is released, all pointer registers corresponding to the\nresource should be invalidated. The verifier use release_references() to\ndo this job, by apply __mark_reg_unknown() to each relevant register.\n\nIt will give these registers the type of SCALAR_VALUE. A register that\nwill contain a pointer value at runtime, but of type SCALAR_VALUE, which\nmay allow the unprivileged user to get a kernel pointer by storing this\nregister into a map.\n\nUsing __mark_reg_not_init() while NOT allow_ptr_leaks can mitigate this\nproblem.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-704"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:12Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-p8w7-qmqj-w8gv/GHSA-p8w7-qmqj-w8gv.json b/advisories/unreviewed/2025/05/GHSA-p8w7-qmqj-w8gv/GHSA-p8w7-qmqj-w8gv.json
new file mode 100644
index 00000000000..0955e2516c1
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-p8w7-qmqj-w8gv/GHSA-p8w7-qmqj-w8gv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p8w7-qmqj-w8gv",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47475"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artbees JupiterX Core allows Stored XSS. This issue affects JupiterX Core: from n/a through 4.8.11.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47475"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/jupiterx-core/vulnerability/wordpress-jupiterx-core-4-8-11-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-p98w-xrc8-4w6x/GHSA-p98w-xrc8-4w6x.json b/advisories/unreviewed/2025/05/GHSA-p98w-xrc8-4w6x/GHSA-p98w-xrc8-4w6x.json
index 704aedb9c2b..489856d64cb 100644
--- a/advisories/unreviewed/2025/05/GHSA-p98w-xrc8-4w6x/GHSA-p98w-xrc8-4w6x.json
+++ b/advisories/unreviewed/2025/05/GHSA-p98w-xrc8-4w6x/GHSA-p98w-xrc8-4w6x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p98w-xrc8-4w6x",
- "modified": "2025-05-01T15:31:52Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:52Z",
"aliases": [
"CVE-2022-49908"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix memory leak in vhci_write\n\nSyzkaller reports a memory leak as follows:\n====================================\nBUG: memory leak\nunreferenced object 0xffff88810d81ac00 (size 240):\n [...]\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [] __alloc_skb+0x1f9/0x270 net/core/skbuff.c:418\n [] alloc_skb include/linux/skbuff.h:1257 [inline]\n [] bt_skb_alloc include/net/bluetooth/bluetooth.h:469 [inline]\n [] vhci_get_user drivers/bluetooth/hci_vhci.c:391 [inline]\n [] vhci_write+0x5f/0x230 drivers/bluetooth/hci_vhci.c:511\n [] call_write_iter include/linux/fs.h:2192 [inline]\n [] new_sync_write fs/read_write.c:491 [inline]\n [] vfs_write+0x42d/0x540 fs/read_write.c:578\n [] ksys_write+0x9d/0x160 fs/read_write.c:631\n [] do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n [] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n [] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n====================================\n\nHCI core will uses hci_rx_work() to process frame, which is queued to\nthe hdev->rx_q tail in hci_recv_frame() by HCI driver.\n\nYet the problem is that, HCI core may not free the skb after handling\nACL data packets. To be more specific, when start fragment does not\ncontain the L2CAP length, HCI core just copies skb into conn->rx_skb and\nfinishes frame process in l2cap_recv_acldata(), without freeing the skb,\nwhich triggers the above memory leak.\n\nThis patch solves it by releasing the relative skb, after processing\nthe above case in l2cap_recv_acldata().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:15Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-p9f7-3xg3-4mr6/GHSA-p9f7-3xg3-4mr6.json b/advisories/unreviewed/2025/05/GHSA-p9f7-3xg3-4mr6/GHSA-p9f7-3xg3-4mr6.json
new file mode 100644
index 00000000000..fdd2cd38026
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-p9f7-3xg3-4mr6/GHSA-p9f7-3xg3-4mr6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p9f7-3xg3-4mr6",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47483"
+ ],
+ "details": "Server-Side Request Forgery (SSRF) vulnerability in Iulia Cazan Easy Replace Image allows Server Side Request Forgery. This issue affects Easy Replace Image: from n/a through 3.5.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47483"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/easy-replace-image/vulnerability/wordpress-easy-replace-image-3-5-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-pc3v-pv9f-mwg5/GHSA-pc3v-pv9f-mwg5.json b/advisories/unreviewed/2025/05/GHSA-pc3v-pv9f-mwg5/GHSA-pc3v-pv9f-mwg5.json
new file mode 100644
index 00000000000..beece0eabf3
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-pc3v-pv9f-mwg5/GHSA-pc3v-pv9f-mwg5.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pc3v-pv9f-mwg5",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47623"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Easy PayPal Buy Now Button allows Stored XSS. This issue affects Easy PayPal Buy Now Button: from n/a through 2.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47623"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-ecommerce-paypal/vulnerability/wordpress-easy-paypal-buy-now-button-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-pfxc-3qw6-6wmw/GHSA-pfxc-3qw6-6wmw.json b/advisories/unreviewed/2025/05/GHSA-pfxc-3qw6-6wmw/GHSA-pfxc-3qw6-6wmw.json
new file mode 100644
index 00000000000..3346461547b
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-pfxc-3qw6-6wmw/GHSA-pfxc-3qw6-6wmw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pfxc-3qw6-6wmw",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47525"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder allows Stored XSS. This issue affects Bold Page Builder: from n/a through 5.3.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47525"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/bold-page-builder/vulnerability/wordpress-bold-page-builder-5-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-pg76-q8r9-xqw5/GHSA-pg76-q8r9-xqw5.json b/advisories/unreviewed/2025/05/GHSA-pg76-q8r9-xqw5/GHSA-pg76-q8r9-xqw5.json
index c9cc277c98b..025f9305182 100644
--- a/advisories/unreviewed/2025/05/GHSA-pg76-q8r9-xqw5/GHSA-pg76-q8r9-xqw5.json
+++ b/advisories/unreviewed/2025/05/GHSA-pg76-q8r9-xqw5/GHSA-pg76-q8r9-xqw5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pg76-q8r9-xqw5",
- "modified": "2025-05-01T15:31:49Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49848"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: qcom-qmp-combo: fix NULL-deref on runtime resume\n\nCommit fc64623637da (\"phy: qcom-qmp-combo,usb: add support for separate\nPCS_USB region\") started treating the PCS_USB registers as potentially\nseparate from the PCS registers but used the wrong base when no PCS_USB\noffset has been provided.\n\nFix the PCS_USB base used at runtime resume to prevent dereferencing a\nNULL pointer on platforms that do not provide a PCS_USB offset (e.g.\nSC7180).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:08Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-ph5g-7g8w-3xpp/GHSA-ph5g-7g8w-3xpp.json b/advisories/unreviewed/2025/05/GHSA-ph5g-7g8w-3xpp/GHSA-ph5g-7g8w-3xpp.json
new file mode 100644
index 00000000000..dbf446a36b7
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-ph5g-7g8w-3xpp/GHSA-ph5g-7g8w-3xpp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-ph5g-7g8w-3xpp",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47617"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aharonyan WP Front User Submit / Front Editor allows Stored XSS. This issue affects WP Front User Submit / Front Editor: from n/a through 4.9.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47617"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/front-editor/vulnerability/wordpress-wp-front-user-submit-front-editor-4-9-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-pmj7-4375-32j4/GHSA-pmj7-4375-32j4.json b/advisories/unreviewed/2025/05/GHSA-pmj7-4375-32j4/GHSA-pmj7-4375-32j4.json
index 7f5c04e7fd9..abf5e67fbea 100644
--- a/advisories/unreviewed/2025/05/GHSA-pmj7-4375-32j4/GHSA-pmj7-4375-32j4.json
+++ b/advisories/unreviewed/2025/05/GHSA-pmj7-4375-32j4/GHSA-pmj7-4375-32j4.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pmj7-4375-32j4",
- "modified": "2025-05-01T15:31:52Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49901"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: Fix kmemleak in blk_mq_init_allocated_queue\n\nThere is a kmemleak caused by modprobe null_blk.ko\n\nunreferenced object 0xffff8881acb1f000 (size 1024):\n comm \"modprobe\", pid 836, jiffies 4294971190 (age 27.068s)\n hex dump (first 32 bytes):\n 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........\n ff ff ff ff ff ff ff ff 00 53 99 9e ff ff ff ff .........S......\n backtrace:\n [<000000004a10c249>] kmalloc_node_trace+0x22/0x60\n [<00000000648f7950>] blk_mq_alloc_and_init_hctx+0x289/0x350\n [<00000000af06de0e>] blk_mq_realloc_hw_ctxs+0x2fe/0x3d0\n [<00000000e00c1872>] blk_mq_init_allocated_queue+0x48c/0x1440\n [<00000000d16b4e68>] __blk_mq_alloc_disk+0xc8/0x1c0\n [<00000000d10c98c3>] 0xffffffffc450d69d\n [<00000000b9299f48>] 0xffffffffc4538392\n [<0000000061c39ed6>] do_one_initcall+0xd0/0x4f0\n [<00000000b389383b>] do_init_module+0x1a4/0x680\n [<0000000087cf3542>] load_module+0x6249/0x7110\n [<00000000beba61b8>] __do_sys_finit_module+0x140/0x200\n [<00000000fdcfff51>] do_syscall_64+0x35/0x80\n [<000000003c0f1f71>] entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nThat is because q->ma_ops is set to NULL before blk_release_queue is\ncalled.\n\nblk_mq_init_queue_data\n blk_mq_init_allocated_queue\n blk_mq_realloc_hw_ctxs\n for (i = 0; i < set->nr_hw_queues; i++) {\n old_hctx = xa_load(&q->hctx_table, i);\n if (!blk_mq_alloc_and_init_hctx(.., i, ..))\t\t[1]\n if (!old_hctx)\n\t break;\n\n xa_for_each_start(&q->hctx_table, j, hctx, j)\n blk_mq_exit_hctx(q, set, hctx, j); \t\t\t[2]\n\n if (!q->nr_hw_queues)\t\t\t\t\t[3]\n goto err_hctxs;\n\n err_exit:\n q->mq_ops = NULL;\t\t\t \t\t\t[4]\n\n blk_put_queue\n blk_release_queue\n if (queue_is_mq(q))\t\t\t\t\t[5]\n blk_mq_release(q);\n\n[1]: blk_mq_alloc_and_init_hctx failed at i != 0.\n[2]: The hctxs allocated by [1] are moved to q->unused_hctx_list and\nwill be cleaned up in blk_mq_release.\n[3]: q->nr_hw_queues is 0.\n[4]: Set q->mq_ops to NULL.\n[5]: queue_is_mq returns false due to [4]. And blk_mq_release\nwill not be called. The hctxs in q->unused_hctx_list are leaked.\n\nTo fix it, call blk_release_queue in exception path.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:15Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-pqh4-qfjx-92pf/GHSA-pqh4-qfjx-92pf.json b/advisories/unreviewed/2025/05/GHSA-pqh4-qfjx-92pf/GHSA-pqh4-qfjx-92pf.json
new file mode 100644
index 00000000000..c4dc42abe74
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-pqh4-qfjx-92pf/GHSA-pqh4-qfjx-92pf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pqh4-qfjx-92pf",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47681"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ability, Inc Web Accessibility with Max Access allows Cross Site Request Forgery. This issue affects Web Accessibility with Max Access: from n/a through 2.0.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47681"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/accessibility-toolbar/vulnerability/wordpress-web-accessibility-with-max-access-2-0-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-pvqf-2g4c-x85p/GHSA-pvqf-2g4c-x85p.json b/advisories/unreviewed/2025/05/GHSA-pvqf-2g4c-x85p/GHSA-pvqf-2g4c-x85p.json
new file mode 100644
index 00000000000..a2cb85c6a35
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-pvqf-2g4c-x85p/GHSA-pvqf-2g4c-x85p.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pvqf-2g4c-x85p",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47522"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AWEOS GmbH AWEOS WP Lock allows Stored XSS. This issue affects AWEOS WP Lock: from n/a through 1.4.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47522"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/aweos-wp-lock/vulnerability/wordpress-aweos-wp-lock-1-4-8-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-q2pw-vm7h-xm59/GHSA-q2pw-vm7h-xm59.json b/advisories/unreviewed/2025/05/GHSA-q2pw-vm7h-xm59/GHSA-q2pw-vm7h-xm59.json
new file mode 100644
index 00000000000..b2d4eb4ea33
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-q2pw-vm7h-xm59/GHSA-q2pw-vm7h-xm59.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q2pw-vm7h-xm59",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47629"
+ ],
+ "details": "Deserialization of Untrusted Data vulnerability in Mario Peshev WP-CRM System allows Object Injection. This issue affects WP-CRM System: from n/a through 3.4.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47629"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-crm-system/vulnerability/wordpress-wp-crm-system-3-4-1-php-object-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-q32v-732h-5jhm/GHSA-q32v-732h-5jhm.json b/advisories/unreviewed/2025/05/GHSA-q32v-732h-5jhm/GHSA-q32v-732h-5jhm.json
new file mode 100644
index 00000000000..5d38a218867
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-q32v-732h-5jhm/GHSA-q32v-732h-5jhm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q32v-732h-5jhm",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47496"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress PublishPress Authors allows PHP Local File Inclusion. This issue affects PublishPress Authors: from n/a through 4.7.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47496"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/publishpress-authors/vulnerability/wordpress-publishpress-authors-4-7-5-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-q46q-hq28-h49r/GHSA-q46q-hq28-h49r.json b/advisories/unreviewed/2025/05/GHSA-q46q-hq28-h49r/GHSA-q46q-hq28-h49r.json
new file mode 100644
index 00000000000..fde79ff3045
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-q46q-hq28-h49r/GHSA-q46q-hq28-h49r.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q46q-hq28-h49r",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47494"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON allows PHP Local File Inclusion. This issue affects EventON: from n/a through 2.4.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47494"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/eventon-lite/vulnerability/wordpress-eventon-2-4-1-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-q5h9-q8h3-6wgx/GHSA-q5h9-q8h3-6wgx.json b/advisories/unreviewed/2025/05/GHSA-q5h9-q8h3-6wgx/GHSA-q5h9-q8h3-6wgx.json
new file mode 100644
index 00000000000..0e68b0dd449
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-q5h9-q8h3-6wgx/GHSA-q5h9-q8h3-6wgx.json
@@ -0,0 +1,25 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q5h9-q8h3-6wgx",
+ "modified": "2025-05-07T15:31:41Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2025-2778"
+ ],
+ "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2778"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:57Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-q746-3vhq-vv92/GHSA-q746-3vhq-vv92.json b/advisories/unreviewed/2025/05/GHSA-q746-3vhq-vv92/GHSA-q746-3vhq-vv92.json
new file mode 100644
index 00000000000..ef97b656f70
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-q746-3vhq-vv92/GHSA-q746-3vhq-vv92.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q746-3vhq-vv92",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47590"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in John Dagelmore WPSpeed allows Cross Site Request Forgery. This issue affects WPSpeed: from n/a through 2.6.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47590"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wpspeed/vulnerability/wordpress-wpspeed-2-6-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-q7gf-3q65-vr9c/GHSA-q7gf-3q65-vr9c.json b/advisories/unreviewed/2025/05/GHSA-q7gf-3q65-vr9c/GHSA-q7gf-3q65-vr9c.json
new file mode 100644
index 00000000000..62bb4987529
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-q7gf-3q65-vr9c/GHSA-q7gf-3q65-vr9c.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q7gf-3q65-vr9c",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47632"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raihanul Islam Awesome Gallery allows Stored XSS. This issue affects Awesome Gallery: from n/a through 1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47632"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/awesome-gallery/vulnerability/wordpress-awesome-gallery-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-q88h-2478-95xj/GHSA-q88h-2478-95xj.json b/advisories/unreviewed/2025/05/GHSA-q88h-2478-95xj/GHSA-q88h-2478-95xj.json
new file mode 100644
index 00000000000..4a10a8b1e96
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-q88h-2478-95xj/GHSA-q88h-2478-95xj.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q88h-2478-95xj",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47518"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Stored XSS. This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.3.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47518"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/contact-form-7-paypal-add-on/vulnerability/wordpress-contact-form-7-paypal-stripe-add-on-2-3-4-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-q8fh-47jf-998w/GHSA-q8fh-47jf-998w.json b/advisories/unreviewed/2025/05/GHSA-q8fh-47jf-998w/GHSA-q8fh-47jf-998w.json
new file mode 100644
index 00000000000..6e30ca18f87
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-q8fh-47jf-998w/GHSA-q8fh-47jf-998w.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q8fh-47jf-998w",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47528"
+ ],
+ "details": "Missing Authorization vulnerability in pewilliams Ovation Elements allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ovation Elements: from n/a through 1.1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47528"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ovation-elements/vulnerability/wordpress-ovation-elements-1-1-2-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-qf94-9355-3gff/GHSA-qf94-9355-3gff.json b/advisories/unreviewed/2025/05/GHSA-qf94-9355-3gff/GHSA-qf94-9355-3gff.json
new file mode 100644
index 00000000000..48a7c69f8a4
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-qf94-9355-3gff/GHSA-qf94-9355-3gff.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qf94-9355-3gff",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47635"
+ ],
+ "details": "Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress allows Server Side Request Forgery. This issue affects WebinarPress: from n/a through 1.33.27.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47635"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-webinarsystem/vulnerability/wordpress-webinarpress-1-33-27-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-qg5g-3955-m72m/GHSA-qg5g-3955-m72m.json b/advisories/unreviewed/2025/05/GHSA-qg5g-3955-m72m/GHSA-qg5g-3955-m72m.json
new file mode 100644
index 00000000000..3567438ea04
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-qg5g-3955-m72m/GHSA-qg5g-3955-m72m.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qg5g-3955-m72m",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47592"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lehel Mátyus Legal Terms and Conditions Popup for User Login and WooCommerce Checkout – TPUL allows Stored XSS. This issue affects Legal Terms and Conditions Popup for User Login and WooCommerce Checkout – TPUL: from n/a through 2.0.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47592"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/terms-popup-on-user-login/vulnerability/wordpress-legal-terms-and-conditions-popup-for-user-login-and-woocommerce-checkout-tpul-2-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-qhm8-hv4h-3hgw/GHSA-qhm8-hv4h-3hgw.json b/advisories/unreviewed/2025/05/GHSA-qhm8-hv4h-3hgw/GHSA-qhm8-hv4h-3hgw.json
new file mode 100644
index 00000000000..0d4c90b7007
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-qhm8-hv4h-3hgw/GHSA-qhm8-hv4h-3hgw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qhm8-hv4h-3hgw",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47514"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Eli ELI's Related Posts Footer Links and Widget allows Stored XSS. This issue affects ELI's Related Posts Footer Links and Widget: from n/a through 1.2.04.20.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47514"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/spostarbust/vulnerability/wordpress-eli-s-related-posts-footer-links-and-widget-plugin-1-2-04-20-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-qp6f-hq95-gpp9/GHSA-qp6f-hq95-gpp9.json b/advisories/unreviewed/2025/05/GHSA-qp6f-hq95-gpp9/GHSA-qp6f-hq95-gpp9.json
index 8617e5385e3..45563c54410 100644
--- a/advisories/unreviewed/2025/05/GHSA-qp6f-hq95-gpp9/GHSA-qp6f-hq95-gpp9.json
+++ b/advisories/unreviewed/2025/05/GHSA-qp6f-hq95-gpp9/GHSA-qp6f-hq95-gpp9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qp6f-hq95-gpp9",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49862"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix the msg->req tlv len check in tipc_nl_compat_name_table_dump_header\n\nThis is a follow-up for commit 974cb0e3e7c9 (\"tipc: fix uninit-value\nin tipc_nl_compat_name_table_dump\") where it should have type casted\nsizeof(..) to int to work when TLV_GET_DATA_LEN() returns a negative\nvalue.\n\nsyzbot reported a call trace because of it:\n\n BUG: KMSAN: uninit-value in ...\n tipc_nl_compat_name_table_dump+0x841/0xea0 net/tipc/netlink_compat.c:934\n __tipc_nl_compat_dumpit+0xab2/0x1320 net/tipc/netlink_compat.c:238\n tipc_nl_compat_dumpit+0x991/0xb50 net/tipc/netlink_compat.c:321\n tipc_nl_compat_recv+0xb6e/0x1640 net/tipc/netlink_compat.c:1324\n genl_family_rcv_msg_doit net/netlink/genetlink.c:731 [inline]\n genl_family_rcv_msg net/netlink/genetlink.c:775 [inline]\n genl_rcv_msg+0x103f/0x1260 net/netlink/genetlink.c:792\n netlink_rcv_skb+0x3a5/0x6c0 net/netlink/af_netlink.c:2501\n genl_rcv+0x3c/0x50 net/netlink/genetlink.c:803\n netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]\n netlink_unicast+0xf3b/0x1270 net/netlink/af_netlink.c:1345\n netlink_sendmsg+0x1288/0x1440 net/netlink/af_netlink.c:1921\n sock_sendmsg_nosec net/socket.c:714 [inline]\n sock_sendmsg net/socket.c:734 [inline]",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:11Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-qqhm-4g64-2g2j/GHSA-qqhm-4g64-2g2j.json b/advisories/unreviewed/2025/05/GHSA-qqhm-4g64-2g2j/GHSA-qqhm-4g64-2g2j.json
new file mode 100644
index 00000000000..5ecebbc80f7
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-qqhm-4g64-2g2j/GHSA-qqhm-4g64-2g2j.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qqhm-4g64-2g2j",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47648"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in axima Pays – WooCommerce Payment Gateway allows Stored XSS. This issue affects Pays – WooCommerce Payment Gateway: from n/a through 2.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47648"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/axima-payment-gateway/vulnerability/wordpress-pays-woocommerce-payment-gateway-2-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-qv4w-frx5-8m5q/GHSA-qv4w-frx5-8m5q.json b/advisories/unreviewed/2025/05/GHSA-qv4w-frx5-8m5q/GHSA-qv4w-frx5-8m5q.json
new file mode 100644
index 00000000000..1715c969888
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-qv4w-frx5-8m5q/GHSA-qv4w-frx5-8m5q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qv4w-frx5-8m5q",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47542"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47542"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/simple-calendar-for-elementor/vulnerability/wordpress-simple-calendar-for-elementor-1-6-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-qwhg-2332-j34c/GHSA-qwhg-2332-j34c.json b/advisories/unreviewed/2025/05/GHSA-qwhg-2332-j34c/GHSA-qwhg-2332-j34c.json
new file mode 100644
index 00000000000..30d58097e2c
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-qwhg-2332-j34c/GHSA-qwhg-2332-j34c.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qwhg-2332-j34c",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47606"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways allows Cross Site Request Forgery. This issue affects Simple Giveaways: from n/a through 2.48.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47606"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/giveasap/vulnerability/wordpress-simple-giveaways-2-48-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-qwpq-8r8m-w7j2/GHSA-qwpq-8r8m-w7j2.json b/advisories/unreviewed/2025/05/GHSA-qwpq-8r8m-w7j2/GHSA-qwpq-8r8m-w7j2.json
new file mode 100644
index 00000000000..65adb83a07f
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-qwpq-8r8m-w7j2/GHSA-qwpq-8r8m-w7j2.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qwpq-8r8m-w7j2",
+ "modified": "2025-05-07T15:31:41Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2025-29154"
+ ],
+ "details": "HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/ted/solicitacao_treinamento/, .galera.app/rh/metas/perspectiva_estrategica/edicao/, .galera.app/rh/cadastros/perspectivas/listagem/adc/, .galera.app/escolaridade/listagem/, .galera.app/estados_civis/cadastro/, .galera.app/nivel_hierarquico/listagem/, .galera.app/nivel_decisorio/cadastro/, .galera.app/escolaridade/cadastro/, .galera.app/nivel_decisorio/listagem/, .galera.app/rh/cadastros/perspectivas/listagem/, .galera.app/empresas_grupo/cadastro/, .galera.app/empresas/edicao/, .galera.app/liais/listagem/, .galera.app/noticias/listagem/, .galera.app/gerenciamento-de-ciclo/abertura/cadastrar, .galera.app/colaborador/cadastro/cursos/adc/edicao/, .galera.app/colaborador/cadastro/adc/, .galera.app/cads_aux/escalact/, .galera.app/ncf/tec/cadastro/ct/ .galera.app/rh/metas/painel/, .galera.app/rh/metas/equipe/edicao/, .galera.app/rh/pdi/tipo_recursos/edicao/, .galera.app/rh/pdi/familia_recursos/cadastro/, .galera.app/rh/pdi/fornecedores/edicao/, and .galera.app/rh/pdi/recursos/cadastro/ components.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29154"
+ },
+ {
+ "type": "WEB",
+ "url": "https://wellington-almeida.medium.com/poc-html-injection-0f27e657c962"
+ },
+ {
+ "type": "WEB",
+ "url": "https://worzyus.medium.com/0f27e657c962"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T14:15:42Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-r5px-8rrr-62mx/GHSA-r5px-8rrr-62mx.json b/advisories/unreviewed/2025/05/GHSA-r5px-8rrr-62mx/GHSA-r5px-8rrr-62mx.json
new file mode 100644
index 00000000000..faebcc4d2e3
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-r5px-8rrr-62mx/GHSA-r5px-8rrr-62mx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r5px-8rrr-62mx",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47524"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karim42 Quran multilanguage Text & Audio allows Stored XSS. This issue affects Quran multilanguage Text & Audio: from n/a through 2.3.23.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47524"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/quran-text-multilanguage/vulnerability/wordpress-quran-multilanguage-text-audio-2-3-23-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-r5vg-mjcx-5wm4/GHSA-r5vg-mjcx-5wm4.json b/advisories/unreviewed/2025/05/GHSA-r5vg-mjcx-5wm4/GHSA-r5vg-mjcx-5wm4.json
new file mode 100644
index 00000000000..75f5156a762
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-r5vg-mjcx-5wm4/GHSA-r5vg-mjcx-5wm4.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r5vg-mjcx-5wm4",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47472"
+ ],
+ "details": "Missing Authorization vulnerability in codepeople Music Player for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Music Player for WooCommerce: from n/a through 1.5.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47472"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/music-player-for-woocommerce/vulnerability/wordpress-music-player-for-woocommerce-1-5-1-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-r62r-xg8x-42v8/GHSA-r62r-xg8x-42v8.json b/advisories/unreviewed/2025/05/GHSA-r62r-xg8x-42v8/GHSA-r62r-xg8x-42v8.json
new file mode 100644
index 00000000000..c6ee1f10752
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-r62r-xg8x-42v8/GHSA-r62r-xg8x-42v8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r62r-xg8x-42v8",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47662"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woobox Woobox allows Stored XSS. This issue affects Woobox: from n/a through 1.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47662"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/woobox/vulnerability/wordpress-woobox-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-rc5m-345p-wjp8/GHSA-rc5m-345p-wjp8.json b/advisories/unreviewed/2025/05/GHSA-rc5m-345p-wjp8/GHSA-rc5m-345p-wjp8.json
new file mode 100644
index 00000000000..946d70e65e3
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-rc5m-345p-wjp8/GHSA-rc5m-345p-wjp8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rc5m-345p-wjp8",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47597"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Maulik Vora WP Podcasts Manager allows Cross Site Request Forgery. This issue affects WP Podcasts Manager: from n/a through 1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47597"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-podcasts-manager/vulnerability/wordpress-wp-podcasts-manager-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-rc8q-6743-jh4w/GHSA-rc8q-6743-jh4w.json b/advisories/unreviewed/2025/05/GHSA-rc8q-6743-jh4w/GHSA-rc8q-6743-jh4w.json
index 92bd795b596..d4d6c6fe7eb 100644
--- a/advisories/unreviewed/2025/05/GHSA-rc8q-6743-jh4w/GHSA-rc8q-6743-jh4w.json
+++ b/advisories/unreviewed/2025/05/GHSA-rc8q-6743-jh4w/GHSA-rc8q-6743-jh4w.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rc8q-6743-jh4w",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49853"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macvlan: fix memory leaks of macvlan_common_newlink\n\nkmemleak reports memory leaks in macvlan_common_newlink, as follows:\n\n ip link add link eth0 name .. type macvlan mode source macaddr add\n \n\nkmemleak reports:\n\nunreferenced object 0xffff8880109bb140 (size 64):\n comm \"ip\", pid 284, jiffies 4294986150 (age 430.108s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 b8 aa 5a 12 80 88 ff ff ..........Z.....\n 80 1b fa 0d 80 88 ff ff 1e ff ac af c7 c1 6b 6b ..............kk\n backtrace:\n [] kmem_cache_alloc_trace+0x1c7/0x300\n [] macvlan_hash_add_source+0x45/0xc0\n [] macvlan_changelink_sources+0xd7/0x170\n [] macvlan_common_newlink+0x38c/0x5a0\n [] macvlan_newlink+0xe/0x20\n [] __rtnl_newlink+0x7af/0xa50\n [] rtnl_newlink+0x48/0x70\n ...\n\nIn the scenario where the macvlan mode is configured as 'source',\nmacvlan_changelink_sources() will be execured to reconfigure list of\nremote source mac addresses, at the same time, if register_netdevice()\nreturn an error, the resource generated by macvlan_changelink_sources()\nis not cleaned up.\n\nUsing this patch, in the case of an error, it will execute\nmacvlan_flush_sources() to ensure that the resource is cleaned up.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:08Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-rcx8-5gmg-pvvp/GHSA-rcx8-5gmg-pvvp.json b/advisories/unreviewed/2025/05/GHSA-rcx8-5gmg-pvvp/GHSA-rcx8-5gmg-pvvp.json
new file mode 100644
index 00000000000..3c2a323906a
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-rcx8-5gmg-pvvp/GHSA-rcx8-5gmg-pvvp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rcx8-5gmg-pvvp",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47675"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woobox Woobox allows DOM-Based XSS. This issue affects Woobox: from n/a through 1.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47675"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/woobox/vulnerability/wordpress-woobox-1-6-cross-site-scripting-xss-vulnerability-2?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-rfjj-g3fv-9v95/GHSA-rfjj-g3fv-9v95.json b/advisories/unreviewed/2025/05/GHSA-rfjj-g3fv-9v95/GHSA-rfjj-g3fv-9v95.json
new file mode 100644
index 00000000000..a704729cc16
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-rfjj-g3fv-9v95/GHSA-rfjj-g3fv-9v95.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rfjj-g3fv-9v95",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47679"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RS WP THEMES RS WP Book Showcase allows DOM-Based XSS. This issue affects RS WP Book Showcase: from n/a through 6.7.40.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47679"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/rs-wp-books-showcase/vulnerability/wordpress-rs-wp-book-showcase-6-7-40-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-rghx-5x43-hx29/GHSA-rghx-5x43-hx29.json b/advisories/unreviewed/2025/05/GHSA-rghx-5x43-hx29/GHSA-rghx-5x43-hx29.json
new file mode 100644
index 00000000000..1eca805e1fb
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-rghx-5x43-hx29/GHSA-rghx-5x43-hx29.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rghx-5x43-hx29",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47615"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flowdee Amazon Product in a Post allows Stored XSS. This issue affects Amazon Product in a Post: from n/a through 5.2.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47615"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/amazon-product-in-a-post-plugin/vulnerability/wordpress-amazon-product-in-a-post-5-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-rrmw-h9hh-7q5m/GHSA-rrmw-h9hh-7q5m.json b/advisories/unreviewed/2025/05/GHSA-rrmw-h9hh-7q5m/GHSA-rrmw-h9hh-7q5m.json
index a0b25d54eed..ae31d95b169 100644
--- a/advisories/unreviewed/2025/05/GHSA-rrmw-h9hh-7q5m/GHSA-rrmw-h9hh-7q5m.json
+++ b/advisories/unreviewed/2025/05/GHSA-rrmw-h9hh-7q5m/GHSA-rrmw-h9hh-7q5m.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rrmw-h9hh-7q5m",
- "modified": "2025-05-01T15:31:53Z",
+ "modified": "2025-05-07T15:31:28Z",
"published": "2025-05-01T15:31:53Z",
"aliases": [
"CVE-2022-49928"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Fix null-ptr-deref when xps sysfs alloc failed\n\nThere is a null-ptr-deref when xps sysfs alloc failed:\n BUG: KASAN: null-ptr-deref in sysfs_do_create_link_sd+0x40/0xd0\n Read of size 8 at addr 0000000000000030 by task gssproxy/457\n\n CPU: 5 PID: 457 Comm: gssproxy Not tainted 6.0.0-09040-g02357b27ee03 #9\n Call Trace:\n \n dump_stack_lvl+0x34/0x44\n kasan_report+0xa3/0x120\n sysfs_do_create_link_sd+0x40/0xd0\n rpc_sysfs_client_setup+0x161/0x1b0\n rpc_new_client+0x3fc/0x6e0\n rpc_create_xprt+0x71/0x220\n rpc_create+0x1d4/0x350\n gssp_rpc_create+0xc3/0x160\n set_gssp_clnt+0xbc/0x140\n write_gssp+0x116/0x1a0\n proc_reg_write+0xd6/0x130\n vfs_write+0x177/0x690\n ksys_write+0xb9/0x150\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nWhen the xprt_switch sysfs alloc failed, should not add xprt and\nswitch sysfs to it, otherwise, maybe null-ptr-deref; also initialize\nthe 'xps_sysfs' to NULL to avoid oops when destroy it.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:18Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-rvcv-cww4-g53q/GHSA-rvcv-cww4-g53q.json b/advisories/unreviewed/2025/05/GHSA-rvcv-cww4-g53q/GHSA-rvcv-cww4-g53q.json
new file mode 100644
index 00000000000..6c1a7103378
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-rvcv-cww4-g53q/GHSA-rvcv-cww4-g53q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rvcv-cww4-g53q",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47638"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarvesh M Rao WP Discord Invite allows Stored XSS. This issue affects WP Discord Invite: from n/a through 2.5.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47638"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-discord-invite/vulnerability/wordpress-wp-discord-invite-2-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-rvfr-97r3-r2hv/GHSA-rvfr-97r3-r2hv.json b/advisories/unreviewed/2025/05/GHSA-rvfr-97r3-r2hv/GHSA-rvfr-97r3-r2hv.json
new file mode 100644
index 00000000000..de3bc0cee43
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-rvfr-97r3-r2hv/GHSA-rvfr-97r3-r2hv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rvfr-97r3-r2hv",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:42Z",
+ "aliases": [
+ "CVE-2025-47443"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown allows Stored XSS. This issue affects Widget Countdown: from n/a through 2.7.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47443"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/widget-countdown/vulnerability/wordpress-widget-countdown-2-7-4-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:58Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-v2fw-2mw5-cq8j/GHSA-v2fw-2mw5-cq8j.json b/advisories/unreviewed/2025/05/GHSA-v2fw-2mw5-cq8j/GHSA-v2fw-2mw5-cq8j.json
new file mode 100644
index 00000000000..0c5dac6649e
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-v2fw-2mw5-cq8j/GHSA-v2fw-2mw5-cq8j.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v2fw-2mw5-cq8j",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47653"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in tggfref WP-Recall allows PHP Local File Inclusion. This issue affects WP-Recall: from n/a through 16.26.14.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47653"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-recall/vulnerability/wordpress-wp-recall-16-26-14-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-v2p6-fgm7-p99g/GHSA-v2p6-fgm7-p99g.json b/advisories/unreviewed/2025/05/GHSA-v2p6-fgm7-p99g/GHSA-v2p6-fgm7-p99g.json
new file mode 100644
index 00000000000..e71079f2e06
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-v2p6-fgm7-p99g/GHSA-v2p6-fgm7-p99g.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v2p6-fgm7-p99g",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47501"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Atlantic Content Control allows DOM-Based XSS. This issue affects Content Control: from n/a through 2.6.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47501"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/content-control/vulnerability/wordpress-content-control-2-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-v4c8-fph7-qhxg/GHSA-v4c8-fph7-qhxg.json b/advisories/unreviewed/2025/05/GHSA-v4c8-fph7-qhxg/GHSA-v4c8-fph7-qhxg.json
new file mode 100644
index 00000000000..2b1a49e1a80
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-v4c8-fph7-qhxg/GHSA-v4c8-fph7-qhxg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v4c8-fph7-qhxg",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47624"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case allows Cross Site Request Forgery. This issue affects DoFollow Case by Case: from n/a through 3.5.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47624"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/dofollow-case-by-case/vulnerability/wordpress-dofollow-case-by-case-3-5-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-v5hx-jf5m-m3wr/GHSA-v5hx-jf5m-m3wr.json b/advisories/unreviewed/2025/05/GHSA-v5hx-jf5m-m3wr/GHSA-v5hx-jf5m-m3wr.json
new file mode 100644
index 00000000000..ec039f86796
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-v5hx-jf5m-m3wr/GHSA-v5hx-jf5m-m3wr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v5hx-jf5m-m3wr",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47659"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements allows Stored XSS. This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through 1.0.4.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47659"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/void-visual-whmcs-element/vulnerability/wordpress-wpbakery-visual-composer-whmcs-elements-1-0-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-v746-9wxc-9rc8/GHSA-v746-9wxc-9rc8.json b/advisories/unreviewed/2025/05/GHSA-v746-9wxc-9rc8/GHSA-v746-9wxc-9rc8.json
new file mode 100644
index 00000000000..25e0fb3aa7c
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-v746-9wxc-9rc8/GHSA-v746-9wxc-9rc8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v746-9wxc-9rc8",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47464"
+ ],
+ "details": "Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra allows Server Side Request Forgery. This issue affects Solace Extra: from n/a through 1.3.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47464"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/solace-extra/vulnerability/wordpress-solace-extra-1-3-1-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-v7j6-8869-pm3w/GHSA-v7j6-8869-pm3w.json b/advisories/unreviewed/2025/05/GHSA-v7j6-8869-pm3w/GHSA-v7j6-8869-pm3w.json
new file mode 100644
index 00000000000..4264da09030
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-v7j6-8869-pm3w/GHSA-v7j6-8869-pm3w.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v7j6-8869-pm3w",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47507"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Better Search allows DOM-Based XSS. This issue affects Better Search: from n/a through 4.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47507"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/better-search/vulnerability/wordpress-better-search-4-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-vhx4-hxq3-vw9g/GHSA-vhx4-hxq3-vw9g.json b/advisories/unreviewed/2025/05/GHSA-vhx4-hxq3-vw9g/GHSA-vhx4-hxq3-vw9g.json
new file mode 100644
index 00000000000..86085679829
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-vhx4-hxq3-vw9g/GHSA-vhx4-hxq3-vw9g.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vhx4-hxq3-vw9g",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47521"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery allows Stored XSS. This issue affects Robo Gallery: from n/a through 5.0.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47521"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/robo-gallery/vulnerability/wordpress-robo-gallery-5-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-vm29-jh4p-x8cp/GHSA-vm29-jh4p-x8cp.json b/advisories/unreviewed/2025/05/GHSA-vm29-jh4p-x8cp/GHSA-vm29-jh4p-x8cp.json
index 12730731be0..65c46ccf019 100644
--- a/advisories/unreviewed/2025/05/GHSA-vm29-jh4p-x8cp/GHSA-vm29-jh4p-x8cp.json
+++ b/advisories/unreviewed/2025/05/GHSA-vm29-jh4p-x8cp/GHSA-vm29-jh4p-x8cp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vm29-jh4p-x8cp",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49895"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Fix decoder allocation crash\n\nWhen an intermediate port's decoders have been exhausted by existing\nregions, and creating a new region with the port in question in it's\nhierarchical path is attempted, cxl_port_attach_region() fails to find a\nport decoder (as would be expected), and drops into the failure / cleanup\npath.\n\nHowever, during cleanup of the region reference, a sanity check attempts\nto dereference the decoder, which in the above case didn't exist. This\ncauses a NULL pointer dereference BUG.\n\nTo fix this, refactor the decoder allocation and de-allocation into\nhelper routines, and in this 'free' routine, check that the decoder,\n@cxld, is valid before attempting any operations on it.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:14Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-vpxj-g3rg-xj45/GHSA-vpxj-g3rg-xj45.json b/advisories/unreviewed/2025/05/GHSA-vpxj-g3rg-xj45/GHSA-vpxj-g3rg-xj45.json
new file mode 100644
index 00000000000..012edb0f37c
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-vpxj-g3rg-xj45/GHSA-vpxj-g3rg-xj45.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vpxj-g3rg-xj45",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47607"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AppJetty Show All Comments allows Stored XSS. This issue affects Show All Comments: from n/a through 7.0.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47607"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/show-all-comments-in-one-page/vulnerability/wordpress-show-all-comments-7-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-vq36-qmwm-crh2/GHSA-vq36-qmwm-crh2.json b/advisories/unreviewed/2025/05/GHSA-vq36-qmwm-crh2/GHSA-vq36-qmwm-crh2.json
index 7d57320fc28..656e63d9f0e 100644
--- a/advisories/unreviewed/2025/05/GHSA-vq36-qmwm-crh2/GHSA-vq36-qmwm-crh2.json
+++ b/advisories/unreviewed/2025/05/GHSA-vq36-qmwm-crh2/GHSA-vq36-qmwm-crh2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vq36-qmwm-crh2",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49885"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: APEI: Fix integer overflow in ghes_estatus_pool_init()\n\nChange num_ghes from int to unsigned int, preventing an overflow\nand causing subsequent vmalloc() to fail.\n\nThe overflow happens in ghes_estatus_pool_init() when calculating\nlen during execution of the statement below as both multiplication\noperands here are signed int:\n\nlen += (num_ghes * GHES_ESOURCE_PREALLOC_MAX_SIZE);\n\nThe following call trace is observed because of this bug:\n\n[ 9.317108] swapper/0: vmalloc error: size 18446744071562596352, exceeds total pages, mode:0xcc0(GFP_KERNEL), nodemask=(null),cpuset=/,mems_allowed=0-1\n[ 9.317131] Call Trace:\n[ 9.317134] \n[ 9.317137] dump_stack_lvl+0x49/0x5f\n[ 9.317145] dump_stack+0x10/0x12\n[ 9.317146] warn_alloc.cold+0x7b/0xdf\n[ 9.317150] ? __device_attach+0x16a/0x1b0\n[ 9.317155] __vmalloc_node_range+0x702/0x740\n[ 9.317160] ? device_add+0x17f/0x920\n[ 9.317164] ? dev_set_name+0x53/0x70\n[ 9.317166] ? platform_device_add+0xf9/0x240\n[ 9.317168] __vmalloc_node+0x49/0x50\n[ 9.317170] ? ghes_estatus_pool_init+0x43/0xa0\n[ 9.317176] vmalloc+0x21/0x30\n[ 9.317177] ghes_estatus_pool_init+0x43/0xa0\n[ 9.317179] acpi_hest_init+0x129/0x19c\n[ 9.317185] acpi_init+0x434/0x4a4\n[ 9.317188] ? acpi_sleep_proc_init+0x2a/0x2a\n[ 9.317190] do_one_initcall+0x48/0x200\n[ 9.317195] kernel_init_freeable+0x221/0x284\n[ 9.317200] ? rest_init+0xe0/0xe0\n[ 9.317204] kernel_init+0x1a/0x130\n[ 9.317205] ret_from_fork+0x22/0x30\n[ 9.317208] \n\n[ rjw: Subject and changelog edits ]",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:13Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-vvp4-j3wj-9jvq/GHSA-vvp4-j3wj-9jvq.json b/advisories/unreviewed/2025/05/GHSA-vvp4-j3wj-9jvq/GHSA-vvp4-j3wj-9jvq.json
index 6683469cabb..2e342a2910d 100644
--- a/advisories/unreviewed/2025/05/GHSA-vvp4-j3wj-9jvq/GHSA-vvp4-j3wj-9jvq.json
+++ b/advisories/unreviewed/2025/05/GHSA-vvp4-j3wj-9jvq/GHSA-vvp4-j3wj-9jvq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvp4-j3wj-9jvq",
- "modified": "2025-05-01T15:31:49Z",
+ "modified": "2025-05-07T15:31:24Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49837"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix memory leaks in __check_func_call\n\nkmemleak reports this issue:\n\nunreferenced object 0xffff88817139d000 (size 2048):\n comm \"test_progs\", pid 33246, jiffies 4307381979 (age 45851.820s)\n hex dump (first 32 bytes):\n 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<0000000045f075f0>] kmalloc_trace+0x27/0xa0\n [<0000000098b7c90a>] __check_func_call+0x316/0x1230\n [<00000000b4c3c403>] check_helper_call+0x172e/0x4700\n [<00000000aa3875b7>] do_check+0x21d8/0x45e0\n [<000000001147357b>] do_check_common+0x767/0xaf0\n [<00000000b5a595b4>] bpf_check+0x43e3/0x5bc0\n [<0000000011e391b1>] bpf_prog_load+0xf26/0x1940\n [<0000000007f765c0>] __sys_bpf+0xd2c/0x3650\n [<00000000839815d6>] __x64_sys_bpf+0x75/0xc0\n [<00000000946ee250>] do_syscall_64+0x3b/0x90\n [<0000000000506b7f>] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe root case here is: In function prepare_func_exit(), the callee is\nnot released in the abnormal scenario after \"state->curframe--;\". To\nfix, move \"state->curframe--;\" to the very bottom of the function,\nright when we free callee and reset frame[] pointer to NULL, as Andrii\nsuggested.\n\nIn addition, function __check_func_call() has a similar problem. In\nthe abnormal scenario before \"state->curframe++;\", the callee also\nshould be released by free_func_state().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:07Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-w5gf-3538-8cgp/GHSA-w5gf-3538-8cgp.json b/advisories/unreviewed/2025/05/GHSA-w5gf-3538-8cgp/GHSA-w5gf-3538-8cgp.json
new file mode 100644
index 00000000000..4173006d7cf
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-w5gf-3538-8cgp/GHSA-w5gf-3538-8cgp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w5gf-3538-8cgp",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47656"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spiraclethemes Spiraclethemes Site Library allows Stored XSS. This issue affects Spiraclethemes Site Library: from n/a through 1.4.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47656"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/spiraclethemes-site-library/vulnerability/wordpress-spiraclethemes-site-library-1-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-w64c-qgh2-qj9c/GHSA-w64c-qgh2-qj9c.json b/advisories/unreviewed/2025/05/GHSA-w64c-qgh2-qj9c/GHSA-w64c-qgh2-qj9c.json
index 13ce533dfc2..bfda4c4d554 100644
--- a/advisories/unreviewed/2025/05/GHSA-w64c-qgh2-qj9c/GHSA-w64c-qgh2-qj9c.json
+++ b/advisories/unreviewed/2025/05/GHSA-w64c-qgh2-qj9c/GHSA-w64c-qgh2-qj9c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w64c-qgh2-qj9c",
- "modified": "2025-05-05T18:32:52Z",
+ "modified": "2025-05-07T15:31:28Z",
"published": "2025-05-05T18:32:52Z",
"aliases": [
"CVE-2025-45320"
],
"details": "A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-548"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-05T16:15:51Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-w6g9-8wm9-p6qf/GHSA-w6g9-8wm9-p6qf.json b/advisories/unreviewed/2025/05/GHSA-w6g9-8wm9-p6qf/GHSA-w6g9-8wm9-p6qf.json
new file mode 100644
index 00000000000..91b029dca80
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-w6g9-8wm9-p6qf/GHSA-w6g9-8wm9-p6qf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w6g9-8wm9-p6qf",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47495"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blockspare Blockspare allows Stored XSS. This issue affects Blockspare: from n/a through 3.2.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47495"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/blockspare/vulnerability/wordpress-blockspare-3-2-9-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-w77p-v2rp-vmv8/GHSA-w77p-v2rp-vmv8.json b/advisories/unreviewed/2025/05/GHSA-w77p-v2rp-vmv8/GHSA-w77p-v2rp-vmv8.json
index 66652da6e36..e444d854874 100644
--- a/advisories/unreviewed/2025/05/GHSA-w77p-v2rp-vmv8/GHSA-w77p-v2rp-vmv8.json
+++ b/advisories/unreviewed/2025/05/GHSA-w77p-v2rp-vmv8/GHSA-w77p-v2rp-vmv8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w77p-v2rp-vmv8",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49888"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: entry: avoid kprobe recursion\n\nThe cortex_a76_erratum_1463225_debug_handler() function is called when\nhandling debug exceptions (and synchronous exceptions from BRK\ninstructions), and so is called when a probed function executes. If the\ncompiler does not inline cortex_a76_erratum_1463225_debug_handler(), it\ncan be probed.\n\nIf cortex_a76_erratum_1463225_debug_handler() is probed, any debug\nexception or software breakpoint exception will result in recursive\nexceptions leading to a stack overflow. This can be triggered with the\nftrace multiple_probes selftest, and as per the example splat below.\n\nThis is a regression caused by commit:\n\n 6459b8469753e9fe (\"arm64: entry: consolidate Cortex-A76 erratum 1463225 workaround\")\n\n... which removed the NOKPROBE_SYMBOL() annotation associated with the\nfunction.\n\nMy intent was that cortex_a76_erratum_1463225_debug_handler() would be\ninlined into its caller, el1_dbg(), which is marked noinstr and cannot\nbe probed. Mark cortex_a76_erratum_1463225_debug_handler() as\n__always_inline to ensure this.\n\nExample splat prior to this patch (with recursive entries elided):\n\n| # echo p cortex_a76_erratum_1463225_debug_handler > /sys/kernel/debug/tracing/kprobe_events\n| # echo p do_el0_svc >> /sys/kernel/debug/tracing/kprobe_events\n| # echo 1 > /sys/kernel/debug/tracing/events/kprobes/enable\n| Insufficient stack space to handle exception!\n| ESR: 0x0000000096000047 -- DABT (current EL)\n| FAR: 0xffff800009cefff0\n| Task stack: [0xffff800009cf0000..0xffff800009cf4000]\n| IRQ stack: [0xffff800008000000..0xffff800008004000]\n| Overflow stack: [0xffff00007fbc00f0..0xffff00007fbc10f0]\n| CPU: 0 PID: 145 Comm: sh Not tainted 6.0.0 #2\n| Hardware name: linux,dummy-virt (DT)\n| pstate: 604003c5 (nZCv DAIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n| pc : arm64_enter_el1_dbg+0x4/0x20\n| lr : el1_dbg+0x24/0x5c\n| sp : ffff800009cf0000\n| x29: ffff800009cf0000 x28: ffff000002c74740 x27: 0000000000000000\n| x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n| x23: 00000000604003c5 x22: ffff80000801745c x21: 0000aaaac95ac068\n| x20: 00000000f2000004 x19: ffff800009cf0040 x18: 0000000000000000\n| x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n| x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n| x11: 0000000000000010 x10: ffff800008c87190 x9 : ffff800008ca00d0\n| x8 : 000000000000003c x7 : 0000000000000000 x6 : 0000000000000000\n| x5 : 0000000000000000 x4 : 0000000000000000 x3 : 00000000000043a4\n| x2 : 00000000f2000004 x1 : 00000000f2000004 x0 : ffff800009cf0040\n| Kernel panic - not syncing: kernel stack overflow\n| CPU: 0 PID: 145 Comm: sh Not tainted 6.0.0 #2\n| Hardware name: linux,dummy-virt (DT)\n| Call trace:\n| dump_backtrace+0xe4/0x104\n| show_stack+0x18/0x4c\n| dump_stack_lvl+0x64/0x7c\n| dump_stack+0x18/0x38\n| panic+0x14c/0x338\n| test_taint+0x0/0x2c\n| panic_bad_stack+0x104/0x118\n| handle_bad_stack+0x34/0x48\n| __bad_stack+0x78/0x7c\n| arm64_enter_el1_dbg+0x4/0x20\n| el1h_64_sync_handler+0x40/0x98\n| el1h_64_sync+0x64/0x68\n| cortex_a76_erratum_1463225_debug_handler+0x0/0x34\n...\n| el1h_64_sync_handler+0x40/0x98\n| el1h_64_sync+0x64/0x68\n| cortex_a76_erratum_1463225_debug_handler+0x0/0x34\n...\n| el1h_64_sync_handler+0x40/0x98\n| el1h_64_sync+0x64/0x68\n| cortex_a76_erratum_1463225_debug_handler+0x0/0x34\n| el1h_64_sync_handler+0x40/0x98\n| el1h_64_sync+0x64/0x68\n| do_el0_svc+0x0/0x28\n| el0t_64_sync_handler+0x84/0xf0\n| el0t_64_sync+0x18c/0x190\n| Kernel Offset: disabled\n| CPU features: 0x0080,00005021,19001080\n| Memory Limit: none\n| ---[ end Kernel panic - not syncing: kernel stack overflow ]---\n\nWith this patch, cortex_a76_erratum_1463225_debug_handler() is inlined\ninto el1_dbg(), and el1_dbg() cannot be probed:\n\n| # echo p cortex_a76_erratum_1463225_debug_handler > /sys/kernel/debug/tracing/kprobe_events\n| sh: write error: No such file or directory\n| # grep -w cortex_a76_errat\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-787"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:13Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-w89v-8v4p-fj5m/GHSA-w89v-8v4p-fj5m.json b/advisories/unreviewed/2025/05/GHSA-w89v-8v4p-fj5m/GHSA-w89v-8v4p-fj5m.json
new file mode 100644
index 00000000000..cc6dd779b6b
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-w89v-8v4p-fj5m/GHSA-w89v-8v4p-fj5m.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w89v-8v4p-fj5m",
+ "modified": "2025-05-07T15:31:41Z",
+ "published": "2025-05-07T15:31:41Z",
+ "aliases": [
+ "CVE-2025-29152"
+ ],
+ "details": "Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via multiple components, including Strategic Planning Perspective Registration, Training Request, Perspective Editing, Education Registration, Hierarchical Level Registration, Decision Level Registration, Perspective Registration, Company Group Registration, Company Registration, News Registration, Employee Editing, Goal Team Registration, Learning Resource Type Registration, Learning Resource Family Registration, Learning Resource Supplier Registration, and Cycle Maintenance.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29152"
+ },
+ {
+ "type": "WEB",
+ "url": "https://medium.com/@worzyus/poc-2fd1d2ec1eb9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://wellington-almeida.medium.com/poc-2fd1d2ec1eb9"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T14:15:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-w983-x7cf-qq48/GHSA-w983-x7cf-qq48.json b/advisories/unreviewed/2025/05/GHSA-w983-x7cf-qq48/GHSA-w983-x7cf-qq48.json
index ab2c986938f..1da447e4133 100644
--- a/advisories/unreviewed/2025/05/GHSA-w983-x7cf-qq48/GHSA-w983-x7cf-qq48.json
+++ b/advisories/unreviewed/2025/05/GHSA-w983-x7cf-qq48/GHSA-w983-x7cf-qq48.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w983-x7cf-qq48",
- "modified": "2025-05-01T15:31:52Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49892"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Fix use-after-free for dynamic ftrace_ops\n\nKASAN reported a use-after-free with ftrace ops [1]. It was found from\nvmcore that perf had registered two ops with the same content\nsuccessively, both dynamic. After unregistering the second ops, a\nuse-after-free occurred.\n\nIn ftrace_shutdown(), when the second ops is unregistered, the\nFTRACE_UPDATE_CALLS command is not set because there is another enabled\nops with the same content. Also, both ops are dynamic and the ftrace\ncallback function is ftrace_ops_list_func, so the\nFTRACE_UPDATE_TRACE_FUNC command will not be set. Eventually the value\nof 'command' will be 0 and ftrace_shutdown() will skip the rcu\nsynchronization.\n\nHowever, ftrace may be activated. When the ops is released, another CPU\nmay be accessing the ops. Add the missing synchronization to fix this\nproblem.\n\n[1]\nBUG: KASAN: use-after-free in __ftrace_ops_list_func kernel/trace/ftrace.c:7020 [inline]\nBUG: KASAN: use-after-free in ftrace_ops_list_func+0x2b0/0x31c kernel/trace/ftrace.c:7049\nRead of size 8 at addr ffff56551965bbc8 by task syz-executor.2/14468\n\nCPU: 1 PID: 14468 Comm: syz-executor.2 Not tainted 5.10.0 #7\nHardware name: linux,dummy-virt (DT)\nCall trace:\n dump_backtrace+0x0/0x40c arch/arm64/kernel/stacktrace.c:132\n show_stack+0x30/0x40 arch/arm64/kernel/stacktrace.c:196\n __dump_stack lib/dump_stack.c:77 [inline]\n dump_stack+0x1b4/0x248 lib/dump_stack.c:118\n print_address_description.constprop.0+0x28/0x48c mm/kasan/report.c:387\n __kasan_report mm/kasan/report.c:547 [inline]\n kasan_report+0x118/0x210 mm/kasan/report.c:564\n check_memory_region_inline mm/kasan/generic.c:187 [inline]\n __asan_load8+0x98/0xc0 mm/kasan/generic.c:253\n __ftrace_ops_list_func kernel/trace/ftrace.c:7020 [inline]\n ftrace_ops_list_func+0x2b0/0x31c kernel/trace/ftrace.c:7049\n ftrace_graph_call+0x0/0x4\n __might_sleep+0x8/0x100 include/linux/perf_event.h:1170\n __might_fault mm/memory.c:5183 [inline]\n __might_fault+0x58/0x70 mm/memory.c:5171\n do_strncpy_from_user lib/strncpy_from_user.c:41 [inline]\n strncpy_from_user+0x1f4/0x4b0 lib/strncpy_from_user.c:139\n getname_flags+0xb0/0x31c fs/namei.c:149\n getname+0x2c/0x40 fs/namei.c:209\n [...]\n\nAllocated by task 14445:\n kasan_save_stack+0x24/0x50 mm/kasan/common.c:48\n kasan_set_track mm/kasan/common.c:56 [inline]\n __kasan_kmalloc mm/kasan/common.c:479 [inline]\n __kasan_kmalloc.constprop.0+0x110/0x13c mm/kasan/common.c:449\n kasan_kmalloc+0xc/0x14 mm/kasan/common.c:493\n kmem_cache_alloc_trace+0x440/0x924 mm/slub.c:2950\n kmalloc include/linux/slab.h:563 [inline]\n kzalloc include/linux/slab.h:675 [inline]\n perf_event_alloc.part.0+0xb4/0x1350 kernel/events/core.c:11230\n perf_event_alloc kernel/events/core.c:11733 [inline]\n __do_sys_perf_event_open kernel/events/core.c:11831 [inline]\n __se_sys_perf_event_open+0x550/0x15f4 kernel/events/core.c:11723\n __arm64_sys_perf_event_open+0x6c/0x80 kernel/events/core.c:11723\n [...]\n\nFreed by task 14445:\n kasan_save_stack+0x24/0x50 mm/kasan/common.c:48\n kasan_set_track+0x24/0x34 mm/kasan/common.c:56\n kasan_set_free_info+0x20/0x40 mm/kasan/generic.c:358\n __kasan_slab_free.part.0+0x11c/0x1b0 mm/kasan/common.c:437\n __kasan_slab_free mm/kasan/common.c:445 [inline]\n kasan_slab_free+0x2c/0x40 mm/kasan/common.c:446\n slab_free_hook mm/slub.c:1569 [inline]\n slab_free_freelist_hook mm/slub.c:1608 [inline]\n slab_free mm/slub.c:3179 [inline]\n kfree+0x12c/0xc10 mm/slub.c:4176\n perf_event_alloc.part.0+0xa0c/0x1350 kernel/events/core.c:11434\n perf_event_alloc kernel/events/core.c:11733 [inline]\n __do_sys_perf_event_open kernel/events/core.c:11831 [inline]\n __se_sys_perf_event_open+0x550/0x15f4 kernel/events/core.c:11723\n [...]",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:14Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-w9v6-vp56-736p/GHSA-w9v6-vp56-736p.json b/advisories/unreviewed/2025/05/GHSA-w9v6-vp56-736p/GHSA-w9v6-vp56-736p.json
new file mode 100644
index 00000000000..b11edc78620
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-w9v6-vp56-736p/GHSA-w9v6-vp56-736p.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w9v6-vp56-736p",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47545"
+ ],
+ "details": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker allows Leveraging Race Conditions. This issue affects Poll Maker: from n/a through 5.7.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47545"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/poll-maker/vulnerability/wordpress-poll-maker-5-7-7-race-condition-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-362"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-w9wh-q8v9-3rwf/GHSA-w9wh-q8v9-3rwf.json b/advisories/unreviewed/2025/05/GHSA-w9wh-q8v9-3rwf/GHSA-w9wh-q8v9-3rwf.json
index 21bdd237275..62c95359237 100644
--- a/advisories/unreviewed/2025/05/GHSA-w9wh-q8v9-3rwf/GHSA-w9wh-q8v9-3rwf.json
+++ b/advisories/unreviewed/2025/05/GHSA-w9wh-q8v9-3rwf/GHSA-w9wh-q8v9-3rwf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w9wh-q8v9-3rwf",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49889"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Check for NULL cpu_buffer in ring_buffer_wake_waiters()\n\nOn some machines the number of listed CPUs may be bigger than the actual\nCPUs that exist. The tracing subsystem allocates a per_cpu directory with\naccess to the per CPU ring buffer via a cpuX file. But to save space, the\nring buffer will only allocate buffers for online CPUs, even though the\nCPU array will be as big as the nr_cpu_ids.\n\nWith the addition of waking waiters on the ring buffer when closing the\nfile, the ring_buffer_wake_waiters() now needs to make sure that the\nbuffer is allocated (with the irq_work allocated with it) before trying to\nwake waiters, as it will cause a NULL pointer dereference.\n\nWhile debugging this, I added a NULL check for the buffer itself (which is\nOK to do), and also NULL pointer checks against buffer->buffers (which is\nnot fine, and will WARN) as well as making sure the CPU number passed in\nis within the nr_cpu_ids (which is also not fine if it isn't).\n\n\nBugzilla: https://bugzilla.opensuse.org/show_bug.cgi?id=1204705",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:13Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-w9wj-9mfq-r996/GHSA-w9wj-9mfq-r996.json b/advisories/unreviewed/2025/05/GHSA-w9wj-9mfq-r996/GHSA-w9wj-9mfq-r996.json
new file mode 100644
index 00000000000..a65c3e94145
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-w9wj-9mfq-r996/GHSA-w9wj-9mfq-r996.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w9wj-9mfq-r996",
+ "modified": "2025-05-07T15:31:45Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47523"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Lukáš Hartmann Seznam Webmaster allows Cross Site Request Forgery. This issue affects Seznam Webmaster: from n/a through 1.4.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47523"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/seznam-webmaster/vulnerability/wordpress-seznam-webmaster-1-4-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-wcxf-x2c5-mpc6/GHSA-wcxf-x2c5-mpc6.json b/advisories/unreviewed/2025/05/GHSA-wcxf-x2c5-mpc6/GHSA-wcxf-x2c5-mpc6.json
new file mode 100644
index 00000000000..e23913949c3
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-wcxf-x2c5-mpc6/GHSA-wcxf-x2c5-mpc6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wcxf-x2c5-mpc6",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47685"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Moloni Contribuinte Checkout allows Stored XSS. This issue affects Contribuinte Checkout: from n/a through 2.0.02.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47685"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/contribuinte-checkout/vulnerability/wordpress-contribuinte-checkout-plugin-2-0-02-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-wf9v-wfmj-qwwm/GHSA-wf9v-wfmj-qwwm.json b/advisories/unreviewed/2025/05/GHSA-wf9v-wfmj-qwwm/GHSA-wf9v-wfmj-qwwm.json
new file mode 100644
index 00000000000..1948db24081
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-wf9v-wfmj-qwwm/GHSA-wf9v-wfmj-qwwm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wf9v-wfmj-qwwm",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47614"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Chris Clark LessButtons Social Sharing and Statistics allows Cross Site Request Forgery. This issue affects LessButtons Social Sharing and Statistics: from n/a through 1.6.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47614"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/lessbuttons/vulnerability/wordpress-lessbuttons-social-sharing-and-statistics-plugin-1-6-1-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-wfq6-3hgh-29wh/GHSA-wfq6-3hgh-29wh.json b/advisories/unreviewed/2025/05/GHSA-wfq6-3hgh-29wh/GHSA-wfq6-3hgh-29wh.json
new file mode 100644
index 00000000000..83783e3d67f
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-wfq6-3hgh-29wh/GHSA-wfq6-3hgh-29wh.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wfq6-3hgh-29wh",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47661"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 allows Cross Site Request Forgery. This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.11.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47661"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/pgall-for-woocommerce/vulnerability/wordpress-5-2-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-wg4w-j824-5xvr/GHSA-wg4w-j824-5xvr.json b/advisories/unreviewed/2025/05/GHSA-wg4w-j824-5xvr/GHSA-wg4w-j824-5xvr.json
new file mode 100644
index 00000000000..215e297bc21
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-wg4w-j824-5xvr/GHSA-wg4w-j824-5xvr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wg4w-j824-5xvr",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47595"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darshan Saroya Color Your Bar allows Stored XSS. This issue affects Color Your Bar: from n/a through 2.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47595"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/color-your-bar/vulnerability/wordpress-color-your-bar-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-wgr5-655j-9682/GHSA-wgr5-655j-9682.json b/advisories/unreviewed/2025/05/GHSA-wgr5-655j-9682/GHSA-wgr5-655j-9682.json
new file mode 100644
index 00000000000..ba23650b7f3
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-wgr5-655j-9682/GHSA-wgr5-655j-9682.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wgr5-655j-9682",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47594"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Soccer Live Scores allows Cross Site Request Forgery. This issue affects Soccer Live Scores: from n/a through 1.0.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47594"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/soccer-live-scores/vulnerability/wordpress-soccer-live-scores-1-0-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-wqcw-jp7x-gc3r/GHSA-wqcw-jp7x-gc3r.json b/advisories/unreviewed/2025/05/GHSA-wqcw-jp7x-gc3r/GHSA-wqcw-jp7x-gc3r.json
new file mode 100644
index 00000000000..d28c3f587bc
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-wqcw-jp7x-gc3r/GHSA-wqcw-jp7x-gc3r.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wqcw-jp7x-gc3r",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:46Z",
+ "aliases": [
+ "CVE-2025-47589"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store allows DOM-Based XSS. This issue affects Ebook Store: from n/a through 5.8007.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47589"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ebook-store/vulnerability/wordpress-ebook-store-5-8007-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-wwxf-j5j9-9834/GHSA-wwxf-j5j9-9834.json b/advisories/unreviewed/2025/05/GHSA-wwxf-j5j9-9834/GHSA-wwxf-j5j9-9834.json
new file mode 100644
index 00000000000..1843a31362e
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-wwxf-j5j9-9834/GHSA-wwxf-j5j9-9834.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wwxf-j5j9-9834",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47488"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder allows DOM-Based XSS. This issue affects Bold Page Builder: from n/a through 5.3.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47488"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/bold-page-builder/vulnerability/wordpress-bold-page-builder-5-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-wxgf-7f8j-hr6j/GHSA-wxgf-7f8j-hr6j.json b/advisories/unreviewed/2025/05/GHSA-wxgf-7f8j-hr6j/GHSA-wxgf-7f8j-hr6j.json
index a8b2b2be810..e061bef81a6 100644
--- a/advisories/unreviewed/2025/05/GHSA-wxgf-7f8j-hr6j/GHSA-wxgf-7f8j-hr6j.json
+++ b/advisories/unreviewed/2025/05/GHSA-wxgf-7f8j-hr6j/GHSA-wxgf-7f8j-hr6j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxgf-7f8j-hr6j",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:26Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49890"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncapabilities: fix potential memleak on error path from vfs_getxattr_alloc()\n\nIn cap_inode_getsecurity(), we will use vfs_getxattr_alloc() to\ncomplete the memory allocation of tmpbuf, if we have completed\nthe memory allocation of tmpbuf, but failed to call handler->get(...),\nthere will be a memleak in below logic:\n\n |-- ret = (int)vfs_getxattr_alloc(mnt_userns, ...)\n | /* ^^^ alloc for tmpbuf */\n |-- value = krealloc(*xattr_value, error + 1, flags)\n | /* ^^^ alloc memory */\n |-- error = handler->get(handler, ...)\n | /* error! */\n |-- *xattr_value = value\n | /* xattr_value is &tmpbuf (memory leak!) */\n\nSo we will try to free(tmpbuf) after vfs_getxattr_alloc() fails to fix it.\n\n[PM: subject line and backtrace tweaks]",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:14Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-x22f-67h5-f46c/GHSA-x22f-67h5-f46c.json b/advisories/unreviewed/2025/05/GHSA-x22f-67h5-f46c/GHSA-x22f-67h5-f46c.json
new file mode 100644
index 00000000000..5f49d9f3e91
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-x22f-67h5-f46c/GHSA-x22f-67h5-f46c.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x22f-67h5-f46c",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47676"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faiyaz Alam User Login History allows Stored XSS. This issue affects User Login History: from n/a through 2.1.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47676"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/user-login-history/vulnerability/wordpress-user-login-history-2-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-x3xw-8j27-57gc/GHSA-x3xw-8j27-57gc.json b/advisories/unreviewed/2025/05/GHSA-x3xw-8j27-57gc/GHSA-x3xw-8j27-57gc.json
index eba3eebe397..69cce1d13fd 100644
--- a/advisories/unreviewed/2025/05/GHSA-x3xw-8j27-57gc/GHSA-x3xw-8j27-57gc.json
+++ b/advisories/unreviewed/2025/05/GHSA-x3xw-8j27-57gc/GHSA-x3xw-8j27-57gc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x3xw-8j27-57gc",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:49Z",
"aliases": [
"CVE-2022-49857"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: marvell: prestera: fix memory leak in prestera_rxtx_switch_init()\n\nWhen prestera_sdma_switch_init() failed, the memory pointed to by\nsw->rxtx isn't released. Fix it. Only be compiled, not be tested.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:09Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-x5m3-jmmc-c2c5/GHSA-x5m3-jmmc-c2c5.json b/advisories/unreviewed/2025/05/GHSA-x5m3-jmmc-c2c5/GHSA-x5m3-jmmc-c2c5.json
new file mode 100644
index 00000000000..909e05a4706
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-x5m3-jmmc-c2c5/GHSA-x5m3-jmmc-c2c5.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x5m3-jmmc-c2c5",
+ "modified": "2025-05-07T15:31:44Z",
+ "published": "2025-05-07T15:31:44Z",
+ "aliases": [
+ "CVE-2025-47498"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking allows PHP Local File Inclusion. This issue affects Hotel Booking: from n/a through 3.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47498"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/nd-booking/vulnerability/wordpress-hotel-booking-3-6-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-x852-r4h4-jm3r/GHSA-x852-r4h4-jm3r.json b/advisories/unreviewed/2025/05/GHSA-x852-r4h4-jm3r/GHSA-x852-r4h4-jm3r.json
new file mode 100644
index 00000000000..8c0f2deeb43
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-x852-r4h4-jm3r/GHSA-x852-r4h4-jm3r.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x852-r4h4-jm3r",
+ "modified": "2025-05-07T15:31:47Z",
+ "published": "2025-05-07T15:31:47Z",
+ "aliases": [
+ "CVE-2025-47609"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in easymebiz EasyMe Connect allows Cross Site Request Forgery. This issue affects EasyMe Connect: from n/a through 3.0.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47609"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/easyme-connect/vulnerability/wordpress-easyme-connect-3-0-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-xf87-h3fp-vmxm/GHSA-xf87-h3fp-vmxm.json b/advisories/unreviewed/2025/05/GHSA-xf87-h3fp-vmxm/GHSA-xf87-h3fp-vmxm.json
new file mode 100644
index 00000000000..86545f712e0
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-xf87-h3fp-vmxm/GHSA-xf87-h3fp-vmxm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xf87-h3fp-vmxm",
+ "modified": "2025-05-07T15:31:42Z",
+ "published": "2025-05-07T15:31:42Z",
+ "aliases": [
+ "CVE-2025-47440"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Greg Winiarski WPAdverts allows PHP Local File Inclusion. This issue affects WPAdverts: from n/a through 2.2.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47440"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wpadverts/vulnerability/wordpress-wpadverts-2-2-2-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:58Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-xh8p-8v2c-5w7v/GHSA-xh8p-8v2c-5w7v.json b/advisories/unreviewed/2025/05/GHSA-xh8p-8v2c-5w7v/GHSA-xh8p-8v2c-5w7v.json
new file mode 100644
index 00000000000..7619ccbbc0a
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-xh8p-8v2c-5w7v/GHSA-xh8p-8v2c-5w7v.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xh8p-8v2c-5w7v",
+ "modified": "2025-05-07T15:31:46Z",
+ "published": "2025-05-07T15:31:45Z",
+ "aliases": [
+ "CVE-2025-47540"
+ ],
+ "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail allows Retrieve Embedded Sensitive Data. This issue affects weMail: from n/a through 1.14.13.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47540"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wemail/vulnerability/wordpress-wemail-1-14-13-sensitive-data-exposure-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-497"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-xhcp-54vp-9q62/GHSA-xhcp-54vp-9q62.json b/advisories/unreviewed/2025/05/GHSA-xhcp-54vp-9q62/GHSA-xhcp-54vp-9q62.json
new file mode 100644
index 00000000000..79afbf65e7b
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-xhcp-54vp-9q62/GHSA-xhcp-54vp-9q62.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xhcp-54vp-9q62",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47457"
+ ],
+ "details": "Missing Authorization vulnerability in dgamoni LocateAndFilter allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects LocateAndFilter: from n/a through 1.6.16.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47457"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/locateandfilter/vulnerability/wordpress-locateandfilter-1-6-16-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:15:59Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-xq94-j9xm-j8mp/GHSA-xq94-j9xm-j8mp.json b/advisories/unreviewed/2025/05/GHSA-xq94-j9xm-j8mp/GHSA-xq94-j9xm-j8mp.json
index db5ee3fc5e9..022271c91df 100644
--- a/advisories/unreviewed/2025/05/GHSA-xq94-j9xm-j8mp/GHSA-xq94-j9xm-j8mp.json
+++ b/advisories/unreviewed/2025/05/GHSA-xq94-j9xm-j8mp/GHSA-xq94-j9xm-j8mp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xq94-j9xm-j8mp",
- "modified": "2025-05-01T15:31:50Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:50Z",
"aliases": [
"CVE-2022-49864"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix NULL pointer dereference in svm_migrate_to_ram()\n\n./drivers/gpu/drm/amd/amdkfd/kfd_migrate.c:985:58-62: ERROR: p is NULL but dereferenced.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:11Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-xr87-w3x6-8rjw/GHSA-xr87-w3x6-8rjw.json b/advisories/unreviewed/2025/05/GHSA-xr87-w3x6-8rjw/GHSA-xr87-w3x6-8rjw.json
new file mode 100644
index 00000000000..dd707557a9d
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-xr87-w3x6-8rjw/GHSA-xr87-w3x6-8rjw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xr87-w3x6-8rjw",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47674"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Credova Financial Credova_Financial allows Cross Site Request Forgery. This issue affects Credova_Financial: from n/a through 2.5.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47674"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/credova-financial/vulnerability/wordpress-credova-financial-2-5-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-xv68-vxp8-qj76/GHSA-xv68-vxp8-qj76.json b/advisories/unreviewed/2025/05/GHSA-xv68-vxp8-qj76/GHSA-xv68-vxp8-qj76.json
new file mode 100644
index 00000000000..e371bb60589
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-xv68-vxp8-qj76/GHSA-xv68-vxp8-qj76.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xv68-vxp8-qj76",
+ "modified": "2025-05-07T15:31:43Z",
+ "published": "2025-05-07T15:31:43Z",
+ "aliases": [
+ "CVE-2025-47466"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47466"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ultimate-wp-mail/vulnerability/wordpress-ultimate-wp-mail-1-3-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/05/GHSA-xxgf-mjgq-w636/GHSA-xxgf-mjgq-w636.json b/advisories/unreviewed/2025/05/GHSA-xxgf-mjgq-w636/GHSA-xxgf-mjgq-w636.json
index d6dc2de0f34..8fb31e6c526 100644
--- a/advisories/unreviewed/2025/05/GHSA-xxgf-mjgq-w636/GHSA-xxgf-mjgq-w636.json
+++ b/advisories/unreviewed/2025/05/GHSA-xxgf-mjgq-w636/GHSA-xxgf-mjgq-w636.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xxgf-mjgq-w636",
- "modified": "2025-05-01T15:31:51Z",
+ "modified": "2025-05-07T15:31:25Z",
"published": "2025-05-01T15:31:51Z",
"aliases": [
"CVE-2022-49887"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: fix possible refcount leak in vdec_probe()\n\nv4l2_device_unregister need to be called to put the refcount got by\nv4l2_device_register when vdec_probe fails or vdec_remove is called.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -37,7 +42,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-01T15:16:13Z"
diff --git a/advisories/unreviewed/2025/05/GHSA-xxm8-g43m-x669/GHSA-xxm8-g43m-x669.json b/advisories/unreviewed/2025/05/GHSA-xxm8-g43m-x669/GHSA-xxm8-g43m-x669.json
new file mode 100644
index 00000000000..ed4d379f5fa
--- /dev/null
+++ b/advisories/unreviewed/2025/05/GHSA-xxm8-g43m-x669/GHSA-xxm8-g43m-x669.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xxm8-g43m-x669",
+ "modified": "2025-05-07T15:31:48Z",
+ "published": "2025-05-07T15:31:48Z",
+ "aliases": [
+ "CVE-2025-47647"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Sidebar Manager Light allows Cross Site Request Forgery. This issue affects Sidebar Manager Light: from n/a through 1.18.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47647"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/sidebar-manager-light/vulnerability/wordpress-sidebar-manager-light-1-18-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-05-07T15:16:17Z"
+ }
+}
\ No newline at end of file