diff --git a/advisories/unreviewed/2024/07/GHSA-4c34-f6qc-56qv/GHSA-4c34-f6qc-56qv.json b/advisories/unreviewed/2024/07/GHSA-4c34-f6qc-56qv/GHSA-4c34-f6qc-56qv.json index 04313a30ece..149ba06bcc4 100644 --- a/advisories/unreviewed/2024/07/GHSA-4c34-f6qc-56qv/GHSA-4c34-f6qc-56qv.json +++ b/advisories/unreviewed/2024/07/GHSA-4c34-f6qc-56qv/GHSA-4c34-f6qc-56qv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-7jw8-q7xc-w2cq/GHSA-7jw8-q7xc-w2cq.json b/advisories/unreviewed/2024/07/GHSA-7jw8-q7xc-w2cq/GHSA-7jw8-q7xc-w2cq.json index fac940304d9..7f90eb65166 100644 --- a/advisories/unreviewed/2024/07/GHSA-7jw8-q7xc-w2cq/GHSA-7jw8-q7xc-w2cq.json +++ b/advisories/unreviewed/2024/07/GHSA-7jw8-q7xc-w2cq/GHSA-7jw8-q7xc-w2cq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-jrjf-m2v9-j4qr/GHSA-jrjf-m2v9-j4qr.json b/advisories/unreviewed/2024/07/GHSA-jrjf-m2v9-j4qr/GHSA-jrjf-m2v9-j4qr.json index bff94e25b35..b402cca6766 100644 --- a/advisories/unreviewed/2024/07/GHSA-jrjf-m2v9-j4qr/GHSA-jrjf-m2v9-j4qr.json +++ b/advisories/unreviewed/2024/07/GHSA-jrjf-m2v9-j4qr/GHSA-jrjf-m2v9-j4qr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-qjh7-f97r-9p56/GHSA-qjh7-f97r-9p56.json b/advisories/unreviewed/2024/07/GHSA-qjh7-f97r-9p56/GHSA-qjh7-f97r-9p56.json index 2a08eb30148..a46c71a6381 100644 --- a/advisories/unreviewed/2024/07/GHSA-qjh7-f97r-9p56/GHSA-qjh7-f97r-9p56.json +++ b/advisories/unreviewed/2024/07/GHSA-qjh7-f97r-9p56/GHSA-qjh7-f97r-9p56.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rp4m-cvm9-gmvp/GHSA-rp4m-cvm9-gmvp.json b/advisories/unreviewed/2024/07/GHSA-rp4m-cvm9-gmvp/GHSA-rp4m-cvm9-gmvp.json index fc3d79ba81c..b36a61c81db 100644 --- a/advisories/unreviewed/2024/07/GHSA-rp4m-cvm9-gmvp/GHSA-rp4m-cvm9-gmvp.json +++ b/advisories/unreviewed/2024/07/GHSA-rp4m-cvm9-gmvp/GHSA-rp4m-cvm9-gmvp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-vh4q-xf3f-7h4p/GHSA-vh4q-xf3f-7h4p.json b/advisories/unreviewed/2024/07/GHSA-vh4q-xf3f-7h4p/GHSA-vh4q-xf3f-7h4p.json index 3e8c30d5ad3..515ffeb6870 100644 --- a/advisories/unreviewed/2024/07/GHSA-vh4q-xf3f-7h4p/GHSA-vh4q-xf3f-7h4p.json +++ b/advisories/unreviewed/2024/07/GHSA-vh4q-xf3f-7h4p/GHSA-vh4q-xf3f-7h4p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2cp7-pmqc-mq6m/GHSA-2cp7-pmqc-mq6m.json b/advisories/unreviewed/2025/05/GHSA-2cp7-pmqc-mq6m/GHSA-2cp7-pmqc-mq6m.json index 0fb36327643..89cf8726986 100644 --- a/advisories/unreviewed/2025/05/GHSA-2cp7-pmqc-mq6m/GHSA-2cp7-pmqc-mq6m.json +++ b/advisories/unreviewed/2025/05/GHSA-2cp7-pmqc-mq6m/GHSA-2cp7-pmqc-mq6m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3p82-g7cx-7qrf/GHSA-3p82-g7cx-7qrf.json b/advisories/unreviewed/2025/05/GHSA-3p82-g7cx-7qrf/GHSA-3p82-g7cx-7qrf.json index 7c024c81f7a..858bdcda5b2 100644 --- a/advisories/unreviewed/2025/05/GHSA-3p82-g7cx-7qrf/GHSA-3p82-g7cx-7qrf.json +++ b/advisories/unreviewed/2025/05/GHSA-3p82-g7cx-7qrf/GHSA-3p82-g7cx-7qrf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4v8j-rhw9-4w63/GHSA-4v8j-rhw9-4w63.json b/advisories/unreviewed/2025/05/GHSA-4v8j-rhw9-4w63/GHSA-4v8j-rhw9-4w63.json index 8c8f7867c97..fa2bcb418f9 100644 --- a/advisories/unreviewed/2025/05/GHSA-4v8j-rhw9-4w63/GHSA-4v8j-rhw9-4w63.json +++ b/advisories/unreviewed/2025/05/GHSA-4v8j-rhw9-4w63/GHSA-4v8j-rhw9-4w63.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-549c-hv52-vxvm/GHSA-549c-hv52-vxvm.json b/advisories/unreviewed/2025/05/GHSA-549c-hv52-vxvm/GHSA-549c-hv52-vxvm.json new file mode 100644 index 00000000000..4aad9f83415 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-549c-hv52-vxvm/GHSA-549c-hv52-vxvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-549c-hv52-vxvm", + "modified": "2025-05-28T03:30:33Z", + "published": "2025-05-28T03:30:33Z", + "aliases": [ + "CVE-2025-25025" + ], + "details": "IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25025" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234827" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T02:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5548-25gc-qcxx/GHSA-5548-25gc-qcxx.json b/advisories/unreviewed/2025/05/GHSA-5548-25gc-qcxx/GHSA-5548-25gc-qcxx.json index c50167bba90..2b46d7de49f 100644 --- a/advisories/unreviewed/2025/05/GHSA-5548-25gc-qcxx/GHSA-5548-25gc-qcxx.json +++ b/advisories/unreviewed/2025/05/GHSA-5548-25gc-qcxx/GHSA-5548-25gc-qcxx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5578-445g-x8r2/GHSA-5578-445g-x8r2.json b/advisories/unreviewed/2025/05/GHSA-5578-445g-x8r2/GHSA-5578-445g-x8r2.json index 10d99aab6b2..7a167592531 100644 --- a/advisories/unreviewed/2025/05/GHSA-5578-445g-x8r2/GHSA-5578-445g-x8r2.json +++ b/advisories/unreviewed/2025/05/GHSA-5578-445g-x8r2/GHSA-5578-445g-x8r2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9h2c-gmfr-3w4c/GHSA-9h2c-gmfr-3w4c.json b/advisories/unreviewed/2025/05/GHSA-9h2c-gmfr-3w4c/GHSA-9h2c-gmfr-3w4c.json index c2907ddc325..c5587f180a2 100644 --- a/advisories/unreviewed/2025/05/GHSA-9h2c-gmfr-3w4c/GHSA-9h2c-gmfr-3w4c.json +++ b/advisories/unreviewed/2025/05/GHSA-9h2c-gmfr-3w4c/GHSA-9h2c-gmfr-3w4c.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json b/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json index 94656572e7c..d75c81566be 100644 --- a/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json +++ b/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch64-4x3c-w3jq", - "modified": "2025-05-27T21:32:17Z", + "modified": "2025-05-28T03:30:33Z", "published": "2025-05-27T21:32:17Z", "aliases": [ "CVE-2025-5278" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368764" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/27/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-fqj7-rj6h-ppvp/GHSA-fqj7-rj6h-ppvp.json b/advisories/unreviewed/2025/05/GHSA-fqj7-rj6h-ppvp/GHSA-fqj7-rj6h-ppvp.json index 17262450bd1..6aae40191f4 100644 --- a/advisories/unreviewed/2025/05/GHSA-fqj7-rj6h-ppvp/GHSA-fqj7-rj6h-ppvp.json +++ b/advisories/unreviewed/2025/05/GHSA-fqj7-rj6h-ppvp/GHSA-fqj7-rj6h-ppvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fqj7-rj6h-ppvp", - "modified": "2025-05-23T15:31:17Z", + "modified": "2025-05-28T03:30:33Z", "published": "2025-05-23T15:31:17Z", "aliases": [ "CVE-2024-51101" ], "details": "PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-23T15:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hx95-xh6x-vgcq/GHSA-hx95-xh6x-vgcq.json b/advisories/unreviewed/2025/05/GHSA-hx95-xh6x-vgcq/GHSA-hx95-xh6x-vgcq.json index e83429cc83b..f467fc8765d 100644 --- a/advisories/unreviewed/2025/05/GHSA-hx95-xh6x-vgcq/GHSA-hx95-xh6x-vgcq.json +++ b/advisories/unreviewed/2025/05/GHSA-hx95-xh6x-vgcq/GHSA-hx95-xh6x-vgcq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jgv5-6946-fjqx/GHSA-jgv5-6946-fjqx.json b/advisories/unreviewed/2025/05/GHSA-jgv5-6946-fjqx/GHSA-jgv5-6946-fjqx.json index 60bada96851..8651b6e89e3 100644 --- a/advisories/unreviewed/2025/05/GHSA-jgv5-6946-fjqx/GHSA-jgv5-6946-fjqx.json +++ b/advisories/unreviewed/2025/05/GHSA-jgv5-6946-fjqx/GHSA-jgv5-6946-fjqx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jgv5-6946-fjqx", - "modified": "2025-05-23T15:31:17Z", + "modified": "2025-05-28T03:30:33Z", "published": "2025-05-23T15:31:16Z", "aliases": [ "CVE-2024-48702" ], "details": "PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-23T15:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-m5qc-f5cx-qrq3/GHSA-m5qc-f5cx-qrq3.json b/advisories/unreviewed/2025/05/GHSA-m5qc-f5cx-qrq3/GHSA-m5qc-f5cx-qrq3.json index 0f72ee3bf2d..8d0633be814 100644 --- a/advisories/unreviewed/2025/05/GHSA-m5qc-f5cx-qrq3/GHSA-m5qc-f5cx-qrq3.json +++ b/advisories/unreviewed/2025/05/GHSA-m5qc-f5cx-qrq3/GHSA-m5qc-f5cx-qrq3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-m89j-9v2x-qhqj/GHSA-m89j-9v2x-qhqj.json b/advisories/unreviewed/2025/05/GHSA-m89j-9v2x-qhqj/GHSA-m89j-9v2x-qhqj.json index 608c4e3c3dc..2a7baf3ca8f 100644 --- a/advisories/unreviewed/2025/05/GHSA-m89j-9v2x-qhqj/GHSA-m89j-9v2x-qhqj.json +++ b/advisories/unreviewed/2025/05/GHSA-m89j-9v2x-qhqj/GHSA-m89j-9v2x-qhqj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-mpm7-f6gv-ghwx/GHSA-mpm7-f6gv-ghwx.json b/advisories/unreviewed/2025/05/GHSA-mpm7-f6gv-ghwx/GHSA-mpm7-f6gv-ghwx.json index b0a59b151a2..cf0f5e4108f 100644 --- a/advisories/unreviewed/2025/05/GHSA-mpm7-f6gv-ghwx/GHSA-mpm7-f6gv-ghwx.json +++ b/advisories/unreviewed/2025/05/GHSA-mpm7-f6gv-ghwx/GHSA-mpm7-f6gv-ghwx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q22r-fww9-4hjr/GHSA-q22r-fww9-4hjr.json b/advisories/unreviewed/2025/05/GHSA-q22r-fww9-4hjr/GHSA-q22r-fww9-4hjr.json new file mode 100644 index 00000000000..501b5707a3e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q22r-fww9-4hjr/GHSA-q22r-fww9-4hjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q22r-fww9-4hjr", + "modified": "2025-05-28T03:30:33Z", + "published": "2025-05-28T03:30:33Z", + "aliases": [ + "CVE-2025-25026" + ], + "details": "IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25026" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234827" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T02:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q935-66v8-qqrq/GHSA-q935-66v8-qqrq.json b/advisories/unreviewed/2025/05/GHSA-q935-66v8-qqrq/GHSA-q935-66v8-qqrq.json new file mode 100644 index 00000000000..826c59f2233 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q935-66v8-qqrq/GHSA-q935-66v8-qqrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q935-66v8-qqrq", + "modified": "2025-05-28T03:30:34Z", + "published": "2025-05-28T03:30:33Z", + "aliases": [ + "CVE-2025-25029" + ], + "details": "IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25029" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7234827" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-28T02:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qwwx-f8r3-v9pc/GHSA-qwwx-f8r3-v9pc.json b/advisories/unreviewed/2025/05/GHSA-qwwx-f8r3-v9pc/GHSA-qwwx-f8r3-v9pc.json index 60a4bba9f79..9e1616ff5bd 100644 --- a/advisories/unreviewed/2025/05/GHSA-qwwx-f8r3-v9pc/GHSA-qwwx-f8r3-v9pc.json +++ b/advisories/unreviewed/2025/05/GHSA-qwwx-f8r3-v9pc/GHSA-qwwx-f8r3-v9pc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-r53g-69jj-xq7x/GHSA-r53g-69jj-xq7x.json b/advisories/unreviewed/2025/05/GHSA-r53g-69jj-xq7x/GHSA-r53g-69jj-xq7x.json index f5e557eab6f..a2a9418a32b 100644 --- a/advisories/unreviewed/2025/05/GHSA-r53g-69jj-xq7x/GHSA-r53g-69jj-xq7x.json +++ b/advisories/unreviewed/2025/05/GHSA-r53g-69jj-xq7x/GHSA-r53g-69jj-xq7x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wc67-xr83-5fq2/GHSA-wc67-xr83-5fq2.json b/advisories/unreviewed/2025/05/GHSA-wc67-xr83-5fq2/GHSA-wc67-xr83-5fq2.json index 3f90a12abe9..47e1de5c4c8 100644 --- a/advisories/unreviewed/2025/05/GHSA-wc67-xr83-5fq2/GHSA-wc67-xr83-5fq2.json +++ b/advisories/unreviewed/2025/05/GHSA-wc67-xr83-5fq2/GHSA-wc67-xr83-5fq2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wf67-68fh-ggp2/GHSA-wf67-68fh-ggp2.json b/advisories/unreviewed/2025/05/GHSA-wf67-68fh-ggp2/GHSA-wf67-68fh-ggp2.json index e38bb3e6d45..cf5fa24dd20 100644 --- a/advisories/unreviewed/2025/05/GHSA-wf67-68fh-ggp2/GHSA-wf67-68fh-ggp2.json +++ b/advisories/unreviewed/2025/05/GHSA-wf67-68fh-ggp2/GHSA-wf67-68fh-ggp2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wfcx-m66p-g8fw/GHSA-wfcx-m66p-g8fw.json b/advisories/unreviewed/2025/05/GHSA-wfcx-m66p-g8fw/GHSA-wfcx-m66p-g8fw.json index eb03b0d1abe..920a82c5893 100644 --- a/advisories/unreviewed/2025/05/GHSA-wfcx-m66p-g8fw/GHSA-wfcx-m66p-g8fw.json +++ b/advisories/unreviewed/2025/05/GHSA-wfcx-m66p-g8fw/GHSA-wfcx-m66p-g8fw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x2qf-7fp6-459x/GHSA-x2qf-7fp6-459x.json b/advisories/unreviewed/2025/05/GHSA-x2qf-7fp6-459x/GHSA-x2qf-7fp6-459x.json index da34e817f31..25c40dbaaee 100644 --- a/advisories/unreviewed/2025/05/GHSA-x2qf-7fp6-459x/GHSA-x2qf-7fp6-459x.json +++ b/advisories/unreviewed/2025/05/GHSA-x2qf-7fp6-459x/GHSA-x2qf-7fp6-459x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x3hf-596g-m5vx/GHSA-x3hf-596g-m5vx.json b/advisories/unreviewed/2025/05/GHSA-x3hf-596g-m5vx/GHSA-x3hf-596g-m5vx.json index af2203f473a..c48d7b08c04 100644 --- a/advisories/unreviewed/2025/05/GHSA-x3hf-596g-m5vx/GHSA-x3hf-596g-m5vx.json +++ b/advisories/unreviewed/2025/05/GHSA-x3hf-596g-m5vx/GHSA-x3hf-596g-m5vx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x6xg-9w9q-643p/GHSA-x6xg-9w9q-643p.json b/advisories/unreviewed/2025/05/GHSA-x6xg-9w9q-643p/GHSA-x6xg-9w9q-643p.json index e64574e065b..60000595e01 100644 --- a/advisories/unreviewed/2025/05/GHSA-x6xg-9w9q-643p/GHSA-x6xg-9w9q-643p.json +++ b/advisories/unreviewed/2025/05/GHSA-x6xg-9w9q-643p/GHSA-x6xg-9w9q-643p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x6xg-9w9q-643p", - "modified": "2025-05-23T15:31:17Z", + "modified": "2025-05-28T03:30:33Z", "published": "2025-05-23T15:31:17Z", "aliases": [ "CVE-2024-51108" ], "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-23T15:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xgcx-978m-c62h/GHSA-xgcx-978m-c62h.json b/advisories/unreviewed/2025/05/GHSA-xgcx-978m-c62h/GHSA-xgcx-978m-c62h.json index 6586a73d59f..7805fa25c9a 100644 --- a/advisories/unreviewed/2025/05/GHSA-xgcx-978m-c62h/GHSA-xgcx-978m-c62h.json +++ b/advisories/unreviewed/2025/05/GHSA-xgcx-978m-c62h/GHSA-xgcx-978m-c62h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xgcx-978m-c62h", - "modified": "2025-05-23T15:31:17Z", + "modified": "2025-05-28T03:30:33Z", "published": "2025-05-23T15:31:17Z", "aliases": [ "CVE-2024-51107" ], "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-23T15:15:23Z"