From fb4afc00f84431a4108b37424d3bd545fc4f63a2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 3 Jun 2025 15:32:59 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-gfx2-wv94-38hv.json | 6 +- .../GHSA-2f4g-8m4c-65fm.json | 2 +- .../GHSA-6959-gv2v-mf33.json | 6 +- .../GHSA-238j-9f3m-57fr.json | 2 +- .../GHSA-29p6-49p2-4mg8.json | 2 +- .../GHSA-3rp5-4w7x-5cpg.json | 2 +- .../GHSA-45vv-2cpw-48c4.json | 2 +- .../GHSA-53hc-55fr-f547.json | 2 +- .../GHSA-5pwx-2rrr-xcvm.json | 2 +- .../GHSA-5q6v-3768-8xq7.json | 2 +- .../GHSA-7gxp-rm68-3f88.json | 2 +- .../GHSA-7p5c-pch3-5mg6.json | 5 +- .../GHSA-8982-h69p-3jrw.json | 2 +- .../GHSA-9cw8-p5p2-35pf.json | 2 +- .../GHSA-c9w5-439r-97p7.json | 4 +- .../GHSA-cv26-8gj7-xp72.json | 4 +- .../GHSA-fw6m-hgqv-hr8c.json | 2 +- .../GHSA-hjg8-pr7m-gj33.json | 14 +++- .../GHSA-j7h7-7c79-56qf.json | 2 +- .../GHSA-mf5p-qrv5-p33r.json | 2 +- .../GHSA-mjhm-77r9-jwp4.json | 4 +- .../GHSA-mwq3-wq3j-gq4v.json | 3 +- .../GHSA-pp9j-v998-vpq3.json | 2 +- .../GHSA-pqm7-4j5w-6gc7.json | 2 +- .../GHSA-q795-pwf5-9r9x.json | 4 +- .../GHSA-r67f-8hjg-55w3.json | 2 +- .../GHSA-rgqm-fq86-cjh4.json | 2 +- .../GHSA-v46r-x4f9-r3p5.json | 2 +- .../GHSA-v64q-49fj-whh5.json | 2 +- .../GHSA-vv2g-g9cv-8wr2.json | 2 +- .../GHSA-w5jx-c49w-xmwh.json | 2 +- .../GHSA-wwvh-g99g-xv29.json | 2 +- .../GHSA-xj97-9w9q-ffjp.json | 2 +- .../GHSA-xr94-cv8c-7r6v.json | 4 +- .../GHSA-74jq-5jmr-v9vc.json | 3 +- .../GHSA-9j9w-j934-v857.json | 3 +- .../GHSA-gp58-pwh5-69h7.json | 3 +- .../GHSA-hr3q-mjh8-jg39.json | 3 +- .../GHSA-m98g-cw9w-r9qw.json | 4 +- .../GHSA-9c4g-4r76-5rq7.json | 6 +- .../GHSA-cvw4-vc58-fhx4.json | 3 +- .../GHSA-j8r3-cghj-9jhg.json | 22 ++++++- .../GHSA-qrxv-77f5-wrfh.json | 3 +- .../GHSA-23ww-hxf9-47fc.json | 56 ++++++++++++++++ .../GHSA-2pg8-h2j6-28xm.json | 60 +++++++++++++++++ .../GHSA-34vf-c5r4-mxr4.json | 56 ++++++++++++++++ .../GHSA-3784-9734-2v5f.json | 64 +++++++++++++++++++ .../GHSA-3jrw-q59w-mpr2.json | 33 ++++++++++ .../GHSA-444c-5p4x-4xgr.json | 36 +++++++++++ .../GHSA-4g4g-fqw4-prp2.json | 64 +++++++++++++++++++ .../GHSA-5fmq-4fvm-96qg.json | 64 +++++++++++++++++++ .../GHSA-5gr5-vmmr-82g6.json | 37 +++++++++++ .../GHSA-68pj-xrp5-vccj.json | 64 +++++++++++++++++++ .../GHSA-6r6c-684h-9j7p.json | 64 +++++++++++++++++++ .../GHSA-7xxr-hvw9-96cr.json | 33 ++++++++++ .../GHSA-9qvj-rpj8-v5c8.json | 39 +++++++++++ .../GHSA-cr8c-wj8h-x5p3.json | 36 +++++++++++ .../GHSA-fxhf-2c5f-jh3q.json | 56 ++++++++++++++++ .../GHSA-gvwx-c268-xr4p.json | 15 +++-- .../GHSA-h582-52vg-77xv.json | 56 ++++++++++++++++ .../GHSA-j9x6-j7hr-4vpf.json | 56 ++++++++++++++++ .../GHSA-p72v-37h5-753v.json | 60 +++++++++++++++++ .../GHSA-q3gg-7j3x-gpfg.json | 52 +++++++++++++++ .../GHSA-rwr2-gc8x-639j.json | 60 +++++++++++++++++ .../GHSA-vpjw-957p-r9gr.json | 56 ++++++++++++++++ .../GHSA-vq5j-6vrq-2cm6.json | 36 +++++++++++ .../GHSA-x56h-2x3p-c97x.json | 33 ++++++++++ .../GHSA-x828-wp24-7h9m.json | 1 + 68 files changed, 1286 insertions(+), 53 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-23ww-hxf9-47fc/GHSA-23ww-hxf9-47fc.json create mode 100644 advisories/unreviewed/2025/06/GHSA-2pg8-h2j6-28xm/GHSA-2pg8-h2j6-28xm.json create mode 100644 advisories/unreviewed/2025/06/GHSA-34vf-c5r4-mxr4/GHSA-34vf-c5r4-mxr4.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3784-9734-2v5f/GHSA-3784-9734-2v5f.json create mode 100644 advisories/unreviewed/2025/06/GHSA-3jrw-q59w-mpr2/GHSA-3jrw-q59w-mpr2.json create mode 100644 advisories/unreviewed/2025/06/GHSA-444c-5p4x-4xgr/GHSA-444c-5p4x-4xgr.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json create mode 100644 advisories/unreviewed/2025/06/GHSA-5fmq-4fvm-96qg/GHSA-5fmq-4fvm-96qg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-5gr5-vmmr-82g6/GHSA-5gr5-vmmr-82g6.json create mode 100644 advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7xxr-hvw9-96cr/GHSA-7xxr-hvw9-96cr.json create mode 100644 advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json create mode 100644 advisories/unreviewed/2025/06/GHSA-cr8c-wj8h-x5p3/GHSA-cr8c-wj8h-x5p3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-fxhf-2c5f-jh3q/GHSA-fxhf-2c5f-jh3q.json create mode 100644 advisories/unreviewed/2025/06/GHSA-h582-52vg-77xv/GHSA-h582-52vg-77xv.json create mode 100644 advisories/unreviewed/2025/06/GHSA-j9x6-j7hr-4vpf/GHSA-j9x6-j7hr-4vpf.json create mode 100644 advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json create mode 100644 advisories/unreviewed/2025/06/GHSA-q3gg-7j3x-gpfg/GHSA-q3gg-7j3x-gpfg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rwr2-gc8x-639j/GHSA-rwr2-gc8x-639j.json create mode 100644 advisories/unreviewed/2025/06/GHSA-vpjw-957p-r9gr/GHSA-vpjw-957p-r9gr.json create mode 100644 advisories/unreviewed/2025/06/GHSA-vq5j-6vrq-2cm6/GHSA-vq5j-6vrq-2cm6.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x56h-2x3p-c97x/GHSA-x56h-2x3p-c97x.json diff --git a/advisories/unreviewed/2022/05/GHSA-gfx2-wv94-38hv/GHSA-gfx2-wv94-38hv.json b/advisories/unreviewed/2022/05/GHSA-gfx2-wv94-38hv/GHSA-gfx2-wv94-38hv.json index 528660f4fc4..1d7993c7fc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfx2-wv94-38hv/GHSA-gfx2-wv94-38hv.json +++ b/advisories/unreviewed/2022/05/GHSA-gfx2-wv94-38hv/GHSA-gfx2-wv94-38hv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfx2-wv94-38hv", - "modified": "2024-07-25T15:30:34Z", + "modified": "2025-06-03T15:31:01Z", "published": "2022-05-13T01:07:40Z", "aliases": [ "CVE-2019-9978" @@ -58,6 +58,10 @@ { "type": "WEB", "url": "http://packetstormsecurity.com/files/163680/WordPress-Social-Warfare-3.5.2-Remote-Code-Execution.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Jun/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/09/GHSA-2f4g-8m4c-65fm/GHSA-2f4g-8m4c-65fm.json b/advisories/unreviewed/2022/09/GHSA-2f4g-8m4c-65fm/GHSA-2f4g-8m4c-65fm.json index e56f07a6b14..4a687e2641d 100644 --- a/advisories/unreviewed/2022/09/GHSA-2f4g-8m4c-65fm/GHSA-2f4g-8m4c-65fm.json +++ b/advisories/unreviewed/2022/09/GHSA-2f4g-8m4c-65fm/GHSA-2f4g-8m4c-65fm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2f4g-8m4c-65fm", - "modified": "2022-09-22T00:00:30Z", + "modified": "2025-06-03T15:31:02Z", "published": "2022-09-17T00:00:33Z", "aliases": [ "CVE-2022-39009" diff --git a/advisories/unreviewed/2023/12/GHSA-6959-gv2v-mf33/GHSA-6959-gv2v-mf33.json b/advisories/unreviewed/2023/12/GHSA-6959-gv2v-mf33/GHSA-6959-gv2v-mf33.json index 6a54817fcab..a395f80baa0 100644 --- a/advisories/unreviewed/2023/12/GHSA-6959-gv2v-mf33/GHSA-6959-gv2v-mf33.json +++ b/advisories/unreviewed/2023/12/GHSA-6959-gv2v-mf33/GHSA-6959-gv2v-mf33.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6959-gv2v-mf33", - "modified": "2023-12-20T18:30:31Z", + "modified": "2025-06-03T15:31:02Z", "published": "2023-12-13T21:30:32Z", "aliases": [ "CVE-2023-50440" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-238j-9f3m-57fr/GHSA-238j-9f3m-57fr.json b/advisories/unreviewed/2024/01/GHSA-238j-9f3m-57fr/GHSA-238j-9f3m-57fr.json index e30494afb49..860706d77a8 100644 --- a/advisories/unreviewed/2024/01/GHSA-238j-9f3m-57fr/GHSA-238j-9f3m-57fr.json +++ b/advisories/unreviewed/2024/01/GHSA-238j-9f3m-57fr/GHSA-238j-9f3m-57fr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-238j-9f3m-57fr", - "modified": "2024-01-18T21:30:27Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T00:30:26Z", "aliases": [ "CVE-2024-0333" diff --git a/advisories/unreviewed/2024/01/GHSA-29p6-49p2-4mg8/GHSA-29p6-49p2-4mg8.json b/advisories/unreviewed/2024/01/GHSA-29p6-49p2-4mg8/GHSA-29p6-49p2-4mg8.json index 50bde724e5c..896e79a8f82 100644 --- a/advisories/unreviewed/2024/01/GHSA-29p6-49p2-4mg8/GHSA-29p6-49p2-4mg8.json +++ b/advisories/unreviewed/2024/01/GHSA-29p6-49p2-4mg8/GHSA-29p6-49p2-4mg8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-29p6-49p2-4mg8", - "modified": "2024-01-17T21:30:20Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T09:30:35Z", "aliases": [ "CVE-2023-6684" diff --git a/advisories/unreviewed/2024/01/GHSA-3rp5-4w7x-5cpg/GHSA-3rp5-4w7x-5cpg.json b/advisories/unreviewed/2024/01/GHSA-3rp5-4w7x-5cpg/GHSA-3rp5-4w7x-5cpg.json index a628e17ab86..0f1ef072bf9 100644 --- a/advisories/unreviewed/2024/01/GHSA-3rp5-4w7x-5cpg/GHSA-3rp5-4w7x-5cpg.json +++ b/advisories/unreviewed/2024/01/GHSA-3rp5-4w7x-5cpg/GHSA-3rp5-4w7x-5cpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3rp5-4w7x-5cpg", - "modified": "2024-01-11T15:30:27Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T15:30:27Z", "aliases": [ "CVE-2023-6242" diff --git a/advisories/unreviewed/2024/01/GHSA-45vv-2cpw-48c4/GHSA-45vv-2cpw-48c4.json b/advisories/unreviewed/2024/01/GHSA-45vv-2cpw-48c4/GHSA-45vv-2cpw-48c4.json index c78436e015d..7769f179e47 100644 --- a/advisories/unreviewed/2024/01/GHSA-45vv-2cpw-48c4/GHSA-45vv-2cpw-48c4.json +++ b/advisories/unreviewed/2024/01/GHSA-45vv-2cpw-48c4/GHSA-45vv-2cpw-48c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45vv-2cpw-48c4", - "modified": "2024-01-18T00:30:17Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T09:30:36Z", "aliases": [ "CVE-2023-7019" diff --git a/advisories/unreviewed/2024/01/GHSA-53hc-55fr-f547/GHSA-53hc-55fr-f547.json b/advisories/unreviewed/2024/01/GHSA-53hc-55fr-f547/GHSA-53hc-55fr-f547.json index b929f465013..ac747f59009 100644 --- a/advisories/unreviewed/2024/01/GHSA-53hc-55fr-f547/GHSA-53hc-55fr-f547.json +++ b/advisories/unreviewed/2024/01/GHSA-53hc-55fr-f547/GHSA-53hc-55fr-f547.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53hc-55fr-f547", - "modified": "2024-01-22T21:31:06Z", + "modified": "2025-06-03T15:31:18Z", "published": "2024-01-15T09:30:19Z", "aliases": [ "CVE-2024-22028" diff --git a/advisories/unreviewed/2024/01/GHSA-5pwx-2rrr-xcvm/GHSA-5pwx-2rrr-xcvm.json b/advisories/unreviewed/2024/01/GHSA-5pwx-2rrr-xcvm/GHSA-5pwx-2rrr-xcvm.json index ab9f29d8c55..1592647808c 100644 --- a/advisories/unreviewed/2024/01/GHSA-5pwx-2rrr-xcvm/GHSA-5pwx-2rrr-xcvm.json +++ b/advisories/unreviewed/2024/01/GHSA-5pwx-2rrr-xcvm/GHSA-5pwx-2rrr-xcvm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5pwx-2rrr-xcvm", - "modified": "2024-01-17T00:30:19Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T09:30:34Z", "aliases": [ "CVE-2023-6506" diff --git a/advisories/unreviewed/2024/01/GHSA-5q6v-3768-8xq7/GHSA-5q6v-3768-8xq7.json b/advisories/unreviewed/2024/01/GHSA-5q6v-3768-8xq7/GHSA-5q6v-3768-8xq7.json index ad601f4b4ac..1e46b28f9d8 100644 --- a/advisories/unreviewed/2024/01/GHSA-5q6v-3768-8xq7/GHSA-5q6v-3768-8xq7.json +++ b/advisories/unreviewed/2024/01/GHSA-5q6v-3768-8xq7/GHSA-5q6v-3768-8xq7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5q6v-3768-8xq7", - "modified": "2024-01-09T18:30:27Z", + "modified": "2025-06-03T15:31:07Z", "published": "2024-01-09T18:30:27Z", "aliases": [ "CVE-2024-22164" diff --git a/advisories/unreviewed/2024/01/GHSA-7gxp-rm68-3f88/GHSA-7gxp-rm68-3f88.json b/advisories/unreviewed/2024/01/GHSA-7gxp-rm68-3f88/GHSA-7gxp-rm68-3f88.json index 25bec305ad4..c76f1143579 100644 --- a/advisories/unreviewed/2024/01/GHSA-7gxp-rm68-3f88/GHSA-7gxp-rm68-3f88.json +++ b/advisories/unreviewed/2024/01/GHSA-7gxp-rm68-3f88/GHSA-7gxp-rm68-3f88.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7gxp-rm68-3f88", - "modified": "2024-01-18T21:30:31Z", + "modified": "2025-06-03T15:31:16Z", "published": "2024-01-12T15:30:32Z", "aliases": [ "CVE-2023-49258" diff --git a/advisories/unreviewed/2024/01/GHSA-7p5c-pch3-5mg6/GHSA-7p5c-pch3-5mg6.json b/advisories/unreviewed/2024/01/GHSA-7p5c-pch3-5mg6/GHSA-7p5c-pch3-5mg6.json index 9113a52682e..83a084c58b5 100644 --- a/advisories/unreviewed/2024/01/GHSA-7p5c-pch3-5mg6/GHSA-7p5c-pch3-5mg6.json +++ b/advisories/unreviewed/2024/01/GHSA-7p5c-pch3-5mg6/GHSA-7p5c-pch3-5mg6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p5c-pch3-5mg6", - "modified": "2024-01-08T21:30:34Z", + "modified": "2025-06-03T15:31:05Z", "published": "2024-01-08T21:30:34Z", "aliases": [ "CVE-2023-50982" @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-434" + "CWE-434", + "CWE-79" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-8982-h69p-3jrw/GHSA-8982-h69p-3jrw.json b/advisories/unreviewed/2024/01/GHSA-8982-h69p-3jrw/GHSA-8982-h69p-3jrw.json index 0bbd0466787..88e5019af25 100644 --- a/advisories/unreviewed/2024/01/GHSA-8982-h69p-3jrw/GHSA-8982-h69p-3jrw.json +++ b/advisories/unreviewed/2024/01/GHSA-8982-h69p-3jrw/GHSA-8982-h69p-3jrw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8982-h69p-3jrw", - "modified": "2024-01-19T18:30:23Z", + "modified": "2025-06-03T15:31:08Z", "published": "2024-01-10T21:31:07Z", "aliases": [ "CVE-2023-50916" diff --git a/advisories/unreviewed/2024/01/GHSA-9cw8-p5p2-35pf/GHSA-9cw8-p5p2-35pf.json b/advisories/unreviewed/2024/01/GHSA-9cw8-p5p2-35pf/GHSA-9cw8-p5p2-35pf.json index 9e81e02dfb7..f02e759d184 100644 --- a/advisories/unreviewed/2024/01/GHSA-9cw8-p5p2-35pf/GHSA-9cw8-p5p2-35pf.json +++ b/advisories/unreviewed/2024/01/GHSA-9cw8-p5p2-35pf/GHSA-9cw8-p5p2-35pf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9cw8-p5p2-35pf", - "modified": "2024-01-18T18:30:24Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T09:30:36Z", "aliases": [ "CVE-2023-6875" diff --git a/advisories/unreviewed/2024/01/GHSA-c9w5-439r-97p7/GHSA-c9w5-439r-97p7.json b/advisories/unreviewed/2024/01/GHSA-c9w5-439r-97p7/GHSA-c9w5-439r-97p7.json index 4cd39bec07a..4c8c46b008b 100644 --- a/advisories/unreviewed/2024/01/GHSA-c9w5-439r-97p7/GHSA-c9w5-439r-97p7.json +++ b/advisories/unreviewed/2024/01/GHSA-c9w5-439r-97p7/GHSA-c9w5-439r-97p7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-c9w5-439r-97p7", - "modified": "2024-01-09T21:30:34Z", + "modified": "2025-06-03T15:31:02Z", "published": "2024-01-03T03:30:33Z", "aliases": [ "CVE-2023-45722" ], - "details": "HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.\n", + "details": "HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-cv26-8gj7-xp72/GHSA-cv26-8gj7-xp72.json b/advisories/unreviewed/2024/01/GHSA-cv26-8gj7-xp72/GHSA-cv26-8gj7-xp72.json index 135077687a8..58ce93cf2f1 100644 --- a/advisories/unreviewed/2024/01/GHSA-cv26-8gj7-xp72/GHSA-cv26-8gj7-xp72.json +++ b/advisories/unreviewed/2024/01/GHSA-cv26-8gj7-xp72/GHSA-cv26-8gj7-xp72.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cv26-8gj7-xp72", - "modified": "2024-01-03T03:30:33Z", + "modified": "2025-06-03T15:31:02Z", "published": "2024-01-03T03:30:33Z", "aliases": [ "CVE-2023-50345" ], - "details": "HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.\n", + "details": "HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-fw6m-hgqv-hr8c/GHSA-fw6m-hgqv-hr8c.json b/advisories/unreviewed/2024/01/GHSA-fw6m-hgqv-hr8c/GHSA-fw6m-hgqv-hr8c.json index 361da102b22..0b87ac2a8f1 100644 --- a/advisories/unreviewed/2024/01/GHSA-fw6m-hgqv-hr8c/GHSA-fw6m-hgqv-hr8c.json +++ b/advisories/unreviewed/2024/01/GHSA-fw6m-hgqv-hr8c/GHSA-fw6m-hgqv-hr8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fw6m-hgqv-hr8c", - "modified": "2024-01-19T03:30:21Z", + "modified": "2025-06-03T15:31:16Z", "published": "2024-01-12T15:30:32Z", "aliases": [ "CVE-2023-49255" diff --git a/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json b/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json index 4020cfea250..0fc32f5dcfd 100644 --- a/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json +++ b/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hjg8-pr7m-gj33", - "modified": "2024-03-23T03:30:24Z", + "modified": "2025-06-03T15:31:15Z", "published": "2024-01-12T06:30:16Z", "aliases": [ "CVE-2022-48620" @@ -42,6 +42,18 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2XZESYGE6XDWAPFUOX26ZWJV2JWMMM5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2J4UB4KXWCCTZCE53B6SFIREZ57INK7T" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E6RLVLJGDKTEVJP446TFDANHB4LHRAOP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2XZESYGE6XDWAPFUOX26ZWJV2JWMMM5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-j7h7-7c79-56qf/GHSA-j7h7-7c79-56qf.json b/advisories/unreviewed/2024/01/GHSA-j7h7-7c79-56qf/GHSA-j7h7-7c79-56qf.json index 582e9e24141..348b92d89fb 100644 --- a/advisories/unreviewed/2024/01/GHSA-j7h7-7c79-56qf/GHSA-j7h7-7c79-56qf.json +++ b/advisories/unreviewed/2024/01/GHSA-j7h7-7c79-56qf/GHSA-j7h7-7c79-56qf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7h7-7c79-56qf", - "modified": "2024-01-17T21:30:20Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T09:30:35Z", "aliases": [ "CVE-2023-6504" diff --git a/advisories/unreviewed/2024/01/GHSA-mf5p-qrv5-p33r/GHSA-mf5p-qrv5-p33r.json b/advisories/unreviewed/2024/01/GHSA-mf5p-qrv5-p33r/GHSA-mf5p-qrv5-p33r.json index c4856f27ded..106a80fea3e 100644 --- a/advisories/unreviewed/2024/01/GHSA-mf5p-qrv5-p33r/GHSA-mf5p-qrv5-p33r.json +++ b/advisories/unreviewed/2024/01/GHSA-mf5p-qrv5-p33r/GHSA-mf5p-qrv5-p33r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mf5p-qrv5-p33r", - "modified": "2024-01-18T18:30:24Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T09:30:36Z", "aliases": [ "CVE-2023-7071" diff --git a/advisories/unreviewed/2024/01/GHSA-mjhm-77r9-jwp4/GHSA-mjhm-77r9-jwp4.json b/advisories/unreviewed/2024/01/GHSA-mjhm-77r9-jwp4/GHSA-mjhm-77r9-jwp4.json index d05b412cf4b..4a172abc2a0 100644 --- a/advisories/unreviewed/2024/01/GHSA-mjhm-77r9-jwp4/GHSA-mjhm-77r9-jwp4.json +++ b/advisories/unreviewed/2024/01/GHSA-mjhm-77r9-jwp4/GHSA-mjhm-77r9-jwp4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mjhm-77r9-jwp4", - "modified": "2024-01-09T03:30:22Z", + "modified": "2025-06-03T15:31:06Z", "published": "2024-01-09T03:30:22Z", "aliases": [ "CVE-2023-39336" ], - "details": "An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server. ", + "details": "An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/01/GHSA-mwq3-wq3j-gq4v/GHSA-mwq3-wq3j-gq4v.json b/advisories/unreviewed/2024/01/GHSA-mwq3-wq3j-gq4v/GHSA-mwq3-wq3j-gq4v.json index 916989934f1..405e3d6d77f 100644 --- a/advisories/unreviewed/2024/01/GHSA-mwq3-wq3j-gq4v/GHSA-mwq3-wq3j-gq4v.json +++ b/advisories/unreviewed/2024/01/GHSA-mwq3-wq3j-gq4v/GHSA-mwq3-wq3j-gq4v.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-352" + "CWE-352", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-pp9j-v998-vpq3/GHSA-pp9j-v998-vpq3.json b/advisories/unreviewed/2024/01/GHSA-pp9j-v998-vpq3/GHSA-pp9j-v998-vpq3.json index 511175c907d..10105317242 100644 --- a/advisories/unreviewed/2024/01/GHSA-pp9j-v998-vpq3/GHSA-pp9j-v998-vpq3.json +++ b/advisories/unreviewed/2024/01/GHSA-pp9j-v998-vpq3/GHSA-pp9j-v998-vpq3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pp9j-v998-vpq3", - "modified": "2024-01-11T21:31:18Z", + "modified": "2025-06-03T15:31:06Z", "published": "2024-01-09T03:30:22Z", "aliases": [ "CVE-2023-26998" diff --git a/advisories/unreviewed/2024/01/GHSA-pqm7-4j5w-6gc7/GHSA-pqm7-4j5w-6gc7.json b/advisories/unreviewed/2024/01/GHSA-pqm7-4j5w-6gc7/GHSA-pqm7-4j5w-6gc7.json index d14d405fc31..1dbb035468b 100644 --- a/advisories/unreviewed/2024/01/GHSA-pqm7-4j5w-6gc7/GHSA-pqm7-4j5w-6gc7.json +++ b/advisories/unreviewed/2024/01/GHSA-pqm7-4j5w-6gc7/GHSA-pqm7-4j5w-6gc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pqm7-4j5w-6gc7", - "modified": "2024-01-10T15:30:21Z", + "modified": "2025-06-03T15:31:08Z", "published": "2024-01-10T15:30:21Z", "aliases": [ "CVE-2023-6158" diff --git a/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json b/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json index a13b22a1d10..e1fdbb356cb 100644 --- a/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json +++ b/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-r67f-8hjg-55w3/GHSA-r67f-8hjg-55w3.json b/advisories/unreviewed/2024/01/GHSA-r67f-8hjg-55w3/GHSA-r67f-8hjg-55w3.json index 26f594a0b28..583f6d25377 100644 --- a/advisories/unreviewed/2024/01/GHSA-r67f-8hjg-55w3/GHSA-r67f-8hjg-55w3.json +++ b/advisories/unreviewed/2024/01/GHSA-r67f-8hjg-55w3/GHSA-r67f-8hjg-55w3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r67f-8hjg-55w3", - "modified": "2024-01-11T21:31:17Z", + "modified": "2025-06-03T15:31:06Z", "published": "2024-01-08T21:30:34Z", "aliases": [ "CVE-2023-52271" diff --git a/advisories/unreviewed/2024/01/GHSA-rgqm-fq86-cjh4/GHSA-rgqm-fq86-cjh4.json b/advisories/unreviewed/2024/01/GHSA-rgqm-fq86-cjh4/GHSA-rgqm-fq86-cjh4.json index a9e53f4a1c9..3e1bf206177 100644 --- a/advisories/unreviewed/2024/01/GHSA-rgqm-fq86-cjh4/GHSA-rgqm-fq86-cjh4.json +++ b/advisories/unreviewed/2024/01/GHSA-rgqm-fq86-cjh4/GHSA-rgqm-fq86-cjh4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgqm-fq86-cjh4", - "modified": "2024-01-18T18:30:24Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T09:30:36Z", "aliases": [ "CVE-2023-6882" diff --git a/advisories/unreviewed/2024/01/GHSA-v46r-x4f9-r3p5/GHSA-v46r-x4f9-r3p5.json b/advisories/unreviewed/2024/01/GHSA-v46r-x4f9-r3p5/GHSA-v46r-x4f9-r3p5.json index 2a9868f2bc4..28024a780fd 100644 --- a/advisories/unreviewed/2024/01/GHSA-v46r-x4f9-r3p5/GHSA-v46r-x4f9-r3p5.json +++ b/advisories/unreviewed/2024/01/GHSA-v46r-x4f9-r3p5/GHSA-v46r-x4f9-r3p5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v46r-x4f9-r3p5", - "modified": "2024-01-18T00:30:17Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T09:30:36Z", "aliases": [ "CVE-2023-6855" diff --git a/advisories/unreviewed/2024/01/GHSA-v64q-49fj-whh5/GHSA-v64q-49fj-whh5.json b/advisories/unreviewed/2024/01/GHSA-v64q-49fj-whh5/GHSA-v64q-49fj-whh5.json index f82461290ef..f16fe0126df 100644 --- a/advisories/unreviewed/2024/01/GHSA-v64q-49fj-whh5/GHSA-v64q-49fj-whh5.json +++ b/advisories/unreviewed/2024/01/GHSA-v64q-49fj-whh5/GHSA-v64q-49fj-whh5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v64q-49fj-whh5", - "modified": "2024-01-18T21:30:31Z", + "modified": "2025-06-03T15:31:16Z", "published": "2024-01-12T15:30:32Z", "aliases": [ "CVE-2023-49260" diff --git a/advisories/unreviewed/2024/01/GHSA-vv2g-g9cv-8wr2/GHSA-vv2g-g9cv-8wr2.json b/advisories/unreviewed/2024/01/GHSA-vv2g-g9cv-8wr2/GHSA-vv2g-g9cv-8wr2.json index 16fdf6fe24e..d0d73cc4280 100644 --- a/advisories/unreviewed/2024/01/GHSA-vv2g-g9cv-8wr2/GHSA-vv2g-g9cv-8wr2.json +++ b/advisories/unreviewed/2024/01/GHSA-vv2g-g9cv-8wr2/GHSA-vv2g-g9cv-8wr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv2g-g9cv-8wr2", - "modified": "2024-01-17T18:31:36Z", + "modified": "2025-06-03T15:31:13Z", "published": "2024-01-11T09:30:34Z", "aliases": [ "CVE-2023-52031" diff --git a/advisories/unreviewed/2024/01/GHSA-w5jx-c49w-xmwh/GHSA-w5jx-c49w-xmwh.json b/advisories/unreviewed/2024/01/GHSA-w5jx-c49w-xmwh/GHSA-w5jx-c49w-xmwh.json index d1db9bc2b96..fd2d407e236 100644 --- a/advisories/unreviewed/2024/01/GHSA-w5jx-c49w-xmwh/GHSA-w5jx-c49w-xmwh.json +++ b/advisories/unreviewed/2024/01/GHSA-w5jx-c49w-xmwh/GHSA-w5jx-c49w-xmwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w5jx-c49w-xmwh", - "modified": "2024-01-11T15:30:27Z", + "modified": "2025-06-03T15:31:14Z", "published": "2024-01-11T15:30:27Z", "aliases": [ "CVE-2023-6244" diff --git a/advisories/unreviewed/2024/01/GHSA-wwvh-g99g-xv29/GHSA-wwvh-g99g-xv29.json b/advisories/unreviewed/2024/01/GHSA-wwvh-g99g-xv29/GHSA-wwvh-g99g-xv29.json index f40e8f3ece0..6e33a9077bc 100644 --- a/advisories/unreviewed/2024/01/GHSA-wwvh-g99g-xv29/GHSA-wwvh-g99g-xv29.json +++ b/advisories/unreviewed/2024/01/GHSA-wwvh-g99g-xv29/GHSA-wwvh-g99g-xv29.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wwvh-g99g-xv29", - "modified": "2024-01-18T21:30:30Z", + "modified": "2025-06-03T15:31:15Z", "published": "2024-01-12T06:30:16Z", "aliases": [ "CVE-2024-23178" diff --git a/advisories/unreviewed/2024/01/GHSA-xj97-9w9q-ffjp/GHSA-xj97-9w9q-ffjp.json b/advisories/unreviewed/2024/01/GHSA-xj97-9w9q-ffjp/GHSA-xj97-9w9q-ffjp.json index fb52ecb4e44..efabdde827b 100644 --- a/advisories/unreviewed/2024/01/GHSA-xj97-9w9q-ffjp/GHSA-xj97-9w9q-ffjp.json +++ b/advisories/unreviewed/2024/01/GHSA-xj97-9w9q-ffjp/GHSA-xj97-9w9q-ffjp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xj97-9w9q-ffjp", - "modified": "2024-01-18T21:30:30Z", + "modified": "2025-06-03T15:31:15Z", "published": "2024-01-12T06:30:16Z", "aliases": [ "CVE-2024-23177" diff --git a/advisories/unreviewed/2024/01/GHSA-xr94-cv8c-7r6v/GHSA-xr94-cv8c-7r6v.json b/advisories/unreviewed/2024/01/GHSA-xr94-cv8c-7r6v/GHSA-xr94-cv8c-7r6v.json index 9e65f0a3e38..fb92da4a618 100644 --- a/advisories/unreviewed/2024/01/GHSA-xr94-cv8c-7r6v/GHSA-xr94-cv8c-7r6v.json +++ b/advisories/unreviewed/2024/01/GHSA-xr94-cv8c-7r6v/GHSA-xr94-cv8c-7r6v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xr94-cv8c-7r6v", - "modified": "2024-01-12T09:30:29Z", + "modified": "2025-06-03T15:31:15Z", "published": "2024-01-12T09:30:29Z", "aliases": [ "CVE-2023-34061" ], - "details": "Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.\n\n\n\n", + "details": "Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-74jq-5jmr-v9vc/GHSA-74jq-5jmr-v9vc.json b/advisories/unreviewed/2024/04/GHSA-74jq-5jmr-v9vc/GHSA-74jq-5jmr-v9vc.json index 55798478bc5..964486c4bd6 100644 --- a/advisories/unreviewed/2024/04/GHSA-74jq-5jmr-v9vc/GHSA-74jq-5jmr-v9vc.json +++ b/advisories/unreviewed/2024/04/GHSA-74jq-5jmr-v9vc/GHSA-74jq-5jmr-v9vc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-9j9w-j934-v857/GHSA-9j9w-j934-v857.json b/advisories/unreviewed/2024/04/GHSA-9j9w-j934-v857/GHSA-9j9w-j934-v857.json index 4004fc73c7d..b7b6101b220 100644 --- a/advisories/unreviewed/2024/04/GHSA-9j9w-j934-v857/GHSA-9j9w-j934-v857.json +++ b/advisories/unreviewed/2024/04/GHSA-9j9w-j934-v857/GHSA-9j9w-j934-v857.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-gp58-pwh5-69h7/GHSA-gp58-pwh5-69h7.json b/advisories/unreviewed/2024/04/GHSA-gp58-pwh5-69h7/GHSA-gp58-pwh5-69h7.json index 77d6ea1a7fc..a74b6404361 100644 --- a/advisories/unreviewed/2024/04/GHSA-gp58-pwh5-69h7/GHSA-gp58-pwh5-69h7.json +++ b/advisories/unreviewed/2024/04/GHSA-gp58-pwh5-69h7/GHSA-gp58-pwh5-69h7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-hr3q-mjh8-jg39/GHSA-hr3q-mjh8-jg39.json b/advisories/unreviewed/2024/04/GHSA-hr3q-mjh8-jg39/GHSA-hr3q-mjh8-jg39.json index 4c9260e87d8..de84ed8554b 100644 --- a/advisories/unreviewed/2024/04/GHSA-hr3q-mjh8-jg39/GHSA-hr3q-mjh8-jg39.json +++ b/advisories/unreviewed/2024/04/GHSA-hr3q-mjh8-jg39/GHSA-hr3q-mjh8-jg39.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json b/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json index a8774f44052..d065755bb58 100644 --- a/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json +++ b/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json b/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json index 15e82079fd7..d658987be78 100644 --- a/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json +++ b/advisories/unreviewed/2025/05/GHSA-9c4g-4r76-5rq7/GHSA-9c4g-4r76-5rq7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9c4g-4r76-5rq7", - "modified": "2025-05-15T15:31:26Z", + "modified": "2025-06-03T15:31:24Z", "published": "2025-05-15T15:31:26Z", "aliases": [ "CVE-2025-4696" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.567683" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586589" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-cvw4-vc58-fhx4/GHSA-cvw4-vc58-fhx4.json b/advisories/unreviewed/2025/05/GHSA-cvw4-vc58-fhx4/GHSA-cvw4-vc58-fhx4.json index e5054bc283d..fbf613b6b4b 100644 --- a/advisories/unreviewed/2025/05/GHSA-cvw4-vc58-fhx4/GHSA-cvw4-vc58-fhx4.json +++ b/advisories/unreviewed/2025/05/GHSA-cvw4-vc58-fhx4/GHSA-cvw4-vc58-fhx4.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json b/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json index 13579703ad4..ea81dafd162 100644 --- a/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json +++ b/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8r3-cghj-9jhg", - "modified": "2025-05-19T12:30:33Z", + "modified": "2025-06-03T15:31:24Z", "published": "2025-05-15T15:31:27Z", "aliases": [ "CVE-2025-4516" @@ -27,14 +27,34 @@ "type": "WEB", "url": "https://github.com/python/cpython/pull/129648" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b" + }, { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74" diff --git a/advisories/unreviewed/2025/05/GHSA-qrxv-77f5-wrfh/GHSA-qrxv-77f5-wrfh.json b/advisories/unreviewed/2025/05/GHSA-qrxv-77f5-wrfh/GHSA-qrxv-77f5-wrfh.json index 95d6e3f9403..50f53a592c1 100644 --- a/advisories/unreviewed/2025/05/GHSA-qrxv-77f5-wrfh/GHSA-qrxv-77f5-wrfh.json +++ b/advisories/unreviewed/2025/05/GHSA-qrxv-77f5-wrfh/GHSA-qrxv-77f5-wrfh.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-23ww-hxf9-47fc/GHSA-23ww-hxf9-47fc.json b/advisories/unreviewed/2025/06/GHSA-23ww-hxf9-47fc/GHSA-23ww-hxf9-47fc.json new file mode 100644 index 00000000000..060fa923bd9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-23ww-hxf9-47fc/GHSA-23ww-hxf9-47fc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23ww-hxf9-47fc", + "modified": "2025-06-03T15:31:27Z", + "published": "2025-06-03T15:31:27Z", + "aliases": [ + "CVE-2025-5505" + ], + "details": "A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5505" + }, + { + "type": "WEB", + "url": "https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/A3002RU_V2/XSS_virtual_server" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584662" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2pg8-h2j6-28xm/GHSA-2pg8-h2j6-28xm.json b/advisories/unreviewed/2025/06/GHSA-2pg8-h2j6-28xm/GHSA-2pg8-h2j6-28xm.json new file mode 100644 index 00000000000..873e30f3517 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2pg8-h2j6-28xm/GHSA-2pg8-h2j6-28xm.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pg8-h2j6-28xm", + "modified": "2025-06-03T15:31:25Z", + "published": "2025-06-03T15:31:25Z", + "aliases": [ + "CVE-2024-12718" + ], + "details": "Allows modifying some file metadata (e.g. last modified) with filter=\"data\" or file permissions (chmod) with filter=\"tar\" of files outside the extraction directory.\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12718" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/issues/127987" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/issues/135034" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/pull/135037" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-34vf-c5r4-mxr4/GHSA-34vf-c5r4-mxr4.json b/advisories/unreviewed/2025/06/GHSA-34vf-c5r4-mxr4/GHSA-34vf-c5r4-mxr4.json new file mode 100644 index 00000000000..f397d7b9d17 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-34vf-c5r4-mxr4/GHSA-34vf-c5r4-mxr4.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34vf-c5r4-mxr4", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-5502" + ], + "details": "A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this issue is the function formMapReboot of the file /boafrm/formMapReboot. The manipulation of the argument deviceMacAddr leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5502" + }, + { + "type": "WEB", + "url": "https://github.com/Yhuanhuan01/TOTOlink/blob/main/TOTOlink-x15.md#poc1-code-injection" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310916" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310916" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.583562" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3784-9734-2v5f/GHSA-3784-9734-2v5f.json b/advisories/unreviewed/2025/06/GHSA-3784-9734-2v5f/GHSA-3784-9734-2v5f.json new file mode 100644 index 00000000000..68d94b8885c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3784-9734-2v5f/GHSA-3784-9734-2v5f.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3784-9734-2v5f", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-5501" + ], + "details": "A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_handle_path_switch_request_transfer of the file src/smf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to reachable assertion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named 2daa44adab762c47a8cef69cc984946973a845b3. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5501" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/issues/3909" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/issues/3909#issuecomment-2926682623" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/commit/2daa44adab762c47a8cef69cc984946973a845b3" + }, + { + "type": "WEB", + "url": "https://github.com/user-attachments/files/20362183/AMF.crash.due.to.pathswitchrequest.zip" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310915" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310915" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.582265" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3jrw-q59w-mpr2/GHSA-3jrw-q59w-mpr2.json b/advisories/unreviewed/2025/06/GHSA-3jrw-q59w-mpr2/GHSA-3jrw-q59w-mpr2.json new file mode 100644 index 00000000000..c420c783af1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3jrw-q59w-mpr2/GHSA-3jrw-q59w-mpr2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jrw-q59w-mpr2", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-43925" + ], + "details": "An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the cleartext data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43925" + }, + { + "type": "WEB", + "url": "https://www.unicomsi.com/products/focal-point" + }, + { + "type": "WEB", + "url": "https://www.unicomsi.com/security-advisory" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-444c-5p4x-4xgr/GHSA-444c-5p4x-4xgr.json b/advisories/unreviewed/2025/06/GHSA-444c-5p4x-4xgr/GHSA-444c-5p4x-4xgr.json new file mode 100644 index 00000000000..bb0fb72f79f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-444c-5p4x-4xgr/GHSA-444c-5p4x-4xgr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-444c-5p4x-4xgr", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-46154" + ], + "details": "Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46154" + }, + { + "type": "WEB", + "url": "https://github.com/Yf3te/CVE/blob/main/CVE-2025-46154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json b/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json new file mode 100644 index 00000000000..6c8caa9c102 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g4g-fqw4-prp2", + "modified": "2025-06-03T15:31:25Z", + "published": "2025-06-03T15:31:25Z", + "aliases": [ + "CVE-2025-4138" + ], + "details": "Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4138" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/issues/135034" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/pull/135037" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5fmq-4fvm-96qg/GHSA-5fmq-4fvm-96qg.json b/advisories/unreviewed/2025/06/GHSA-5fmq-4fvm-96qg/GHSA-5fmq-4fvm-96qg.json new file mode 100644 index 00000000000..deabdc6e8e6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5fmq-4fvm-96qg/GHSA-5fmq-4fvm-96qg.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fmq-4fvm-96qg", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-5498" + ], + "details": "A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/is_file of the file include/inc_lib/content/cnt21.readform.inc.php of the component Custom Source Tab. The manipulation of the argument cpage_custom leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.46 and 1.10.9 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5498" + }, + { + "type": "WEB", + "url": "https://github.com/3em0/cve_repo/blob/main/phpwcms/cnt21.readform.inc.php%23file_get_contents.md" + }, + { + "type": "WEB", + "url": "https://github.com/3em0/cve_repo/blob/main/phpwcms/cnt21.readform.inc.php%23is_file.md" + }, + { + "type": "WEB", + "url": "https://github.com/slackero/phpwcms/releases/tag/v1.10.9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310913" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310913" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578054" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578055" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5gr5-vmmr-82g6/GHSA-5gr5-vmmr-82g6.json b/advisories/unreviewed/2025/06/GHSA-5gr5-vmmr-82g6/GHSA-5gr5-vmmr-82g6.json new file mode 100644 index 00000000000..6e8f0d218c5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5gr5-vmmr-82g6/GHSA-5gr5-vmmr-82g6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gr5-vmmr-82g6", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-45855" + ], + "details": "An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45855" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Cafe-Tea/b72d442be434e1dafe7810c938892b06" + }, + { + "type": "WEB", + "url": "https://github.com/erupts/erupt" + }, + { + "type": "WEB", + "url": "https://www.erupt.xyz/#%21" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json b/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json new file mode 100644 index 00000000000..0275fc504e2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68pj-xrp5-vccj", + "modified": "2025-06-03T15:31:25Z", + "published": "2025-06-03T15:31:25Z", + "aliases": [ + "CVE-2025-4330" + ], + "details": "Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4330" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/issues/135034" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/pull/135037" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json b/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json new file mode 100644 index 00000000000..15cb5d5e572 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r6c-684h-9j7p", + "modified": "2025-06-03T15:31:25Z", + "published": "2025-06-03T15:31:25Z", + "aliases": [ + "CVE-2025-4517" + ], + "details": "Allows arbitrary filesystem writes outside the extraction directory during extraction with filter=\"data\".\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4517" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/issues/135034" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/pull/135037" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7xxr-hvw9-96cr/GHSA-7xxr-hvw9-96cr.json b/advisories/unreviewed/2025/06/GHSA-7xxr-hvw9-96cr/GHSA-7xxr-hvw9-96cr.json new file mode 100644 index 00000000000..32b74f24943 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7xxr-hvw9-96cr/GHSA-7xxr-hvw9-96cr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xxr-hvw9-96cr", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-43924" + ], + "details": "Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (for /fp/admin/settings/loginpage) and the rootserviceurl parameter in FriendsController (for /fp/admin/settings/friends), entered by an admin, allow stored XSS.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43924" + }, + { + "type": "WEB", + "url": "https://www.unicomsi.com/products/focal-point" + }, + { + "type": "WEB", + "url": "https://www.unicomsi.com/security-advisory" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json b/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json new file mode 100644 index 00000000000..de5d4aa4576 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9qvj-rpj8-v5c8/GHSA-9qvj-rpj8-v5c8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qvj-rpj8-v5c8", + "modified": "2025-06-03T15:31:27Z", + "published": "2025-06-03T15:31:27Z", + "aliases": [ + "CVE-2025-46548" + ], + "details": "If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied.\n\n\nUsers that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46548" + }, + { + "type": "WEB", + "url": "https://github.com/akka/akka-management/pull/1385" + }, + { + "type": "WEB", + "url": "https://github.com/apache/pekko-management/pull/418" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/tnd84hj9w0ggjcft6cp12q67d5jzhp66" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cr8c-wj8h-x5p3/GHSA-cr8c-wj8h-x5p3.json b/advisories/unreviewed/2025/06/GHSA-cr8c-wj8h-x5p3/GHSA-cr8c-wj8h-x5p3.json new file mode 100644 index 00000000000..628751f47bd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cr8c-wj8h-x5p3/GHSA-cr8c-wj8h-x5p3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr8c-wj8h-x5p3", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2024-45655" + ], + "details": "IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45655" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235378" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fxhf-2c5f-jh3q/GHSA-fxhf-2c5f-jh3q.json b/advisories/unreviewed/2025/06/GHSA-fxhf-2c5f-jh3q/GHSA-fxhf-2c5f-jh3q.json new file mode 100644 index 00000000000..0c6f5762b50 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fxhf-2c5f-jh3q/GHSA-fxhf-2c5f-jh3q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxhf-2c5f-jh3q", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-5495" + ], + "details": "A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknown part of the component URL Handler. The manipulation with the input %00currentsetting.htm leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This issue appears to have been circulating as an 0day since 2024.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5495" + }, + { + "type": "WEB", + "url": "https://github.com/Shuanunio/CVE_Requests/blob/main/Netgear/WNR614/ACL%20bypass%20Vulnerability%20in%20Netgear%20WNR614.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310911" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310911" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584939" + }, + { + "type": "WEB", + "url": "https://www.netgear.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gvwx-c268-xr4p/GHSA-gvwx-c268-xr4p.json b/advisories/unreviewed/2025/06/GHSA-gvwx-c268-xr4p/GHSA-gvwx-c268-xr4p.json index c269b228025..fa22445e0f8 100644 --- a/advisories/unreviewed/2025/06/GHSA-gvwx-c268-xr4p/GHSA-gvwx-c268-xr4p.json +++ b/advisories/unreviewed/2025/06/GHSA-gvwx-c268-xr4p/GHSA-gvwx-c268-xr4p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gvwx-c268-xr4p", - "modified": "2025-06-02T18:30:52Z", + "modified": "2025-06-03T15:31:24Z", "published": "2025-06-02T18:30:52Z", "aliases": [ "CVE-2025-27953" ], "details": "An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T18:15:23Z" diff --git a/advisories/unreviewed/2025/06/GHSA-h582-52vg-77xv/GHSA-h582-52vg-77xv.json b/advisories/unreviewed/2025/06/GHSA-h582-52vg-77xv/GHSA-h582-52vg-77xv.json new file mode 100644 index 00000000000..1cc53ef806a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h582-52vg-77xv/GHSA-h582-52vg-77xv.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h582-52vg-77xv", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-5497" + ], + "details": "A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been declared as critical. This vulnerability affects unknown code of the file include/inc_module/mod_feedimport/inc/processing.inc.php of the component Feedimport Module. The manipulation of the argument cnt_text leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.46 and 1.10.9 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5497" + }, + { + "type": "WEB", + "url": "https://github.com/3em0/cve_repo/blob/main/phpwcms/phar%20vulnerability%20in%20phpwcms.md" + }, + { + "type": "WEB", + "url": "https://github.com/slackero/phpwcms/releases/tag/v1.10.9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.577999" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j9x6-j7hr-4vpf/GHSA-j9x6-j7hr-4vpf.json b/advisories/unreviewed/2025/06/GHSA-j9x6-j7hr-4vpf/GHSA-j9x6-j7hr-4vpf.json new file mode 100644 index 00000000000..03a753593d3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j9x6-j7hr-4vpf/GHSA-j9x6-j7hr-4vpf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9x6-j7hr-4vpf", + "modified": "2025-06-03T15:31:27Z", + "published": "2025-06-03T15:31:27Z", + "aliases": [ + "CVE-2025-5504" + ], + "details": "A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWsc. The manipulation of the argument peerRptPin leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5504" + }, + { + "type": "WEB", + "url": "https://github.com/fizz-is-on-the-way/Iot_vuls/blob/main/X2000R/RCE_formWsc/RCE_formWsc.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584660" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json b/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json new file mode 100644 index 00000000000..300043402e8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p72v-37h5-753v/GHSA-p72v-37h5-753v.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p72v-37h5-753v", + "modified": "2025-06-03T15:31:25Z", + "published": "2025-06-03T15:31:25Z", + "aliases": [ + "CVE-2025-4435" + ], + "details": "When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4435" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/issues/135034" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/pull/135037" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01" + }, + { + "type": "WEB", + "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-682" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q3gg-7j3x-gpfg/GHSA-q3gg-7j3x-gpfg.json b/advisories/unreviewed/2025/06/GHSA-q3gg-7j3x-gpfg/GHSA-q3gg-7j3x-gpfg.json new file mode 100644 index 00000000000..442f6377af6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q3gg-7j3x-gpfg/GHSA-q3gg-7j3x-gpfg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3gg-7j3x-gpfg", + "modified": "2025-06-03T15:31:27Z", + "published": "2025-06-03T15:31:27Z", + "aliases": [ + "CVE-2025-5503" + ], + "details": "A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the function formMapReboot of the file /boafrm/formMapReboot. The manipulation of the argument deviceMacAddr leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5503" + }, + { + "type": "WEB", + "url": "https://github.com/Yhuanhuan01/TOTOlink/blob/main/TOTOlink-x15.md#poc2-stack_overflow" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310917" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310917" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rwr2-gc8x-639j/GHSA-rwr2-gc8x-639j.json b/advisories/unreviewed/2025/06/GHSA-rwr2-gc8x-639j/GHSA-rwr2-gc8x-639j.json new file mode 100644 index 00000000000..44caf2f1f0c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rwr2-gc8x-639j/GHSA-rwr2-gc8x-639j.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwr2-gc8x-639j", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-5499" + ], + "details": "A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the file image_resized.php. The manipulation of the argument imgfile leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9.46 and 1.10.9 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5499" + }, + { + "type": "WEB", + "url": "https://github.com/3em0/cve_repo/blob/main/phpwcms/image_resized%23getimagesize.md" + }, + { + "type": "WEB", + "url": "https://github.com/slackero/phpwcms/releases/tag/v1.10.9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310914" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310914" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578082" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578083" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vpjw-957p-r9gr/GHSA-vpjw-957p-r9gr.json b/advisories/unreviewed/2025/06/GHSA-vpjw-957p-r9gr/GHSA-vpjw-957p-r9gr.json new file mode 100644 index 00000000000..525517f3430 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vpjw-957p-r9gr/GHSA-vpjw-957p-r9gr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpjw-957p-r9gr", + "modified": "2025-06-03T15:31:27Z", + "published": "2025-06-03T15:31:27Z", + "aliases": [ + "CVE-2025-5506" + ], + "details": "A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as problematic. Affected is an unknown function of the component NAT Mapping Page. The manipulation of the argument Comment leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5506" + }, + { + "type": "WEB", + "url": "https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/A3002RU_V2/XSS_Nat_Mapping" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584663" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vq5j-6vrq-2cm6/GHSA-vq5j-6vrq-2cm6.json b/advisories/unreviewed/2025/06/GHSA-vq5j-6vrq-2cm6/GHSA-vq5j-6vrq-2cm6.json new file mode 100644 index 00000000000..8163fdfb215 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vq5j-6vrq-2cm6/GHSA-vq5j-6vrq-2cm6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq5j-6vrq-2cm6", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-36564" + ], + "details": "Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36564" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000325203/dsa-2025-224" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x56h-2x3p-c97x/GHSA-x56h-2x3p-c97x.json b/advisories/unreviewed/2025/06/GHSA-x56h-2x3p-c97x/GHSA-x56h-2x3p-c97x.json new file mode 100644 index 00000000000..789868ac8d1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x56h-2x3p-c97x/GHSA-x56h-2x3p-c97x.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x56h-2x3p-c97x", + "modified": "2025-06-03T15:31:26Z", + "published": "2025-06-03T15:31:26Z", + "aliases": [ + "CVE-2025-43923" + ], + "details": "An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via the image parameter during a delete report image operation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43923" + }, + { + "type": "WEB", + "url": "https://www.unicomsi.com/products/focal-point" + }, + { + "type": "WEB", + "url": "https://www.unicomsi.com/security-advisory" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x828-wp24-7h9m/GHSA-x828-wp24-7h9m.json b/advisories/unreviewed/2025/06/GHSA-x828-wp24-7h9m/GHSA-x828-wp24-7h9m.json index 6b58adbed3d..7efd40c6040 100644 --- a/advisories/unreviewed/2025/06/GHSA-x828-wp24-7h9m/GHSA-x828-wp24-7h9m.json +++ b/advisories/unreviewed/2025/06/GHSA-x828-wp24-7h9m/GHSA-x828-wp24-7h9m.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], "severity": "HIGH",