diff --git a/advisories/unreviewed/2022/05/GHSA-7v25-cx6v-gf9w/GHSA-7v25-cx6v-gf9w.json b/advisories/unreviewed/2022/05/GHSA-7v25-cx6v-gf9w/GHSA-7v25-cx6v-gf9w.json index 5713a49778e..33b9606a4cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v25-cx6v-gf9w/GHSA-7v25-cx6v-gf9w.json +++ b/advisories/unreviewed/2022/05/GHSA-7v25-cx6v-gf9w/GHSA-7v25-cx6v-gf9w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v25-cx6v-gf9w", - "modified": "2022-05-14T01:48:06Z", + "modified": "2025-06-05T15:31:16Z", "published": "2022-05-14T01:48:06Z", "aliases": [ "CVE-2018-18760" diff --git a/advisories/unreviewed/2023/11/GHSA-7mcq-5qp3-w599/GHSA-7mcq-5qp3-w599.json b/advisories/unreviewed/2023/11/GHSA-7mcq-5qp3-w599/GHSA-7mcq-5qp3-w599.json index 276cf0fa1d7..05c0301e755 100644 --- a/advisories/unreviewed/2023/11/GHSA-7mcq-5qp3-w599/GHSA-7mcq-5qp3-w599.json +++ b/advisories/unreviewed/2023/11/GHSA-7mcq-5qp3-w599/GHSA-7mcq-5qp3-w599.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-86v4-9wq7-fx97/GHSA-86v4-9wq7-fx97.json b/advisories/unreviewed/2023/11/GHSA-86v4-9wq7-fx97/GHSA-86v4-9wq7-fx97.json index 380c355b619..3571986a6ae 100644 --- a/advisories/unreviewed/2023/11/GHSA-86v4-9wq7-fx97/GHSA-86v4-9wq7-fx97.json +++ b/advisories/unreviewed/2023/11/GHSA-86v4-9wq7-fx97/GHSA-86v4-9wq7-fx97.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-jfww-45p8-3v7v/GHSA-jfww-45p8-3v7v.json b/advisories/unreviewed/2023/11/GHSA-jfww-45p8-3v7v/GHSA-jfww-45p8-3v7v.json index 8c852182c15..60b8b98c0ae 100644 --- a/advisories/unreviewed/2023/11/GHSA-jfww-45p8-3v7v/GHSA-jfww-45p8-3v7v.json +++ b/advisories/unreviewed/2023/11/GHSA-jfww-45p8-3v7v/GHSA-jfww-45p8-3v7v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-q5c3-528w-jr93/GHSA-q5c3-528w-jr93.json b/advisories/unreviewed/2023/11/GHSA-q5c3-528w-jr93/GHSA-q5c3-528w-jr93.json index 25a81953659..a2af245814a 100644 --- a/advisories/unreviewed/2023/11/GHSA-q5c3-528w-jr93/GHSA-q5c3-528w-jr93.json +++ b/advisories/unreviewed/2023/11/GHSA-q5c3-528w-jr93/GHSA-q5c3-528w-jr93.json @@ -31,6 +31,7 @@ "database_specific": { "cwe_ids": [ "CWE-120", + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/05/GHSA-qxgc-qp86-4mg6/GHSA-qxgc-qp86-4mg6.json b/advisories/unreviewed/2024/05/GHSA-qxgc-qp86-4mg6/GHSA-qxgc-qp86-4mg6.json index 961b8a17ab3..10a31446635 100644 --- a/advisories/unreviewed/2024/05/GHSA-qxgc-qp86-4mg6/GHSA-qxgc-qp86-4mg6.json +++ b/advisories/unreviewed/2024/05/GHSA-qxgc-qp86-4mg6/GHSA-qxgc-qp86-4mg6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qxgc-qp86-4mg6", - "modified": "2024-05-15T00:30:38Z", + "modified": "2025-06-05T15:31:20Z", "published": "2024-05-15T00:30:38Z", "aliases": [ "CVE-2024-31483" ], - "details": "An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.\n\n", + "details": "An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-xhph-75hg-j96m/GHSA-xhph-75hg-j96m.json b/advisories/unreviewed/2024/05/GHSA-xhph-75hg-j96m/GHSA-xhph-75hg-j96m.json index f8e3a7b8d30..111ca3ddfe3 100644 --- a/advisories/unreviewed/2024/05/GHSA-xhph-75hg-j96m/GHSA-xhph-75hg-j96m.json +++ b/advisories/unreviewed/2024/05/GHSA-xhph-75hg-j96m/GHSA-xhph-75hg-j96m.json @@ -1,13 +1,22 @@ { "schema_version": "1.4.0", "id": "GHSA-xhph-75hg-j96m", - "modified": "2024-05-21T12:30:53Z", + "modified": "2025-06-05T15:31:20Z", "published": "2024-05-21T12:30:53Z", "aliases": [ "CVE-2024-4420" ], "details": "There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3.  * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input that is not an encoded JSON object, but still a valid encoded JSON element, for example a number or an array. This will crash as Tink just assumes any valid JSON input will contain an object.\n\n\n * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input containing many nested JSON objects. This may result in a stack overflow.\n\n\nWe recommend upgrading to version 2.1.3 or above", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:D/RE:L/U:Green" + } + ], "affected": [], "references": [ { @@ -23,7 +32,7 @@ "cwe_ids": [ "CWE-116" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T12:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6999-6m26-m9xx/GHSA-6999-6m26-m9xx.json b/advisories/unreviewed/2024/11/GHSA-6999-6m26-m9xx/GHSA-6999-6m26-m9xx.json index 6bee1bf7193..5e37fb101b3 100644 --- a/advisories/unreviewed/2024/11/GHSA-6999-6m26-m9xx/GHSA-6999-6m26-m9xx.json +++ b/advisories/unreviewed/2024/11/GHSA-6999-6m26-m9xx/GHSA-6999-6m26-m9xx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6999-6m26-m9xx", - "modified": "2024-11-19T18:31:06Z", + "modified": "2025-06-05T15:31:20Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-48069" ], "details": "A remote code execution (RCE) vulnerability in the component /inventory/doCptimpoptInventory of Weaver Ecology v9.* allows attackers to execute arbitrary code via injecting a crafted payload into the name of an uploaded file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:21Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rf66-cpg6-q99p/GHSA-rf66-cpg6-q99p.json b/advisories/unreviewed/2024/11/GHSA-rf66-cpg6-q99p/GHSA-rf66-cpg6-q99p.json index 4f9addf6051..516a60a6772 100644 --- a/advisories/unreviewed/2024/11/GHSA-rf66-cpg6-q99p/GHSA-rf66-cpg6-q99p.json +++ b/advisories/unreviewed/2024/11/GHSA-rf66-cpg6-q99p/GHSA-rf66-cpg6-q99p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rf66-cpg6-q99p", - "modified": "2024-11-19T18:31:06Z", + "modified": "2025-06-05T15:31:20Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-48072" ], "details": "Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=*&fromTable=HrmResourceManager&whereClause=1%3d1&triggerCondition=1&expression=%3d&fieldValue=1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:21Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xvcg-crx7-qcjv/GHSA-xvcg-crx7-qcjv.json b/advisories/unreviewed/2024/11/GHSA-xvcg-crx7-qcjv/GHSA-xvcg-crx7-qcjv.json index 20c297237e8..b7140e8d23d 100644 --- a/advisories/unreviewed/2024/11/GHSA-xvcg-crx7-qcjv/GHSA-xvcg-crx7-qcjv.json +++ b/advisories/unreviewed/2024/11/GHSA-xvcg-crx7-qcjv/GHSA-xvcg-crx7-qcjv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xvcg-crx7-qcjv", - "modified": "2024-11-19T18:31:06Z", + "modified": "2025-06-05T15:31:20Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-48070" ], "details": "Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:21Z" diff --git a/advisories/unreviewed/2025/01/GHSA-85qx-mfpj-cvj4/GHSA-85qx-mfpj-cvj4.json b/advisories/unreviewed/2025/01/GHSA-85qx-mfpj-cvj4/GHSA-85qx-mfpj-cvj4.json index 5e9624a0748..fd42991487a 100644 --- a/advisories/unreviewed/2025/01/GHSA-85qx-mfpj-cvj4/GHSA-85qx-mfpj-cvj4.json +++ b/advisories/unreviewed/2025/01/GHSA-85qx-mfpj-cvj4/GHSA-85qx-mfpj-cvj4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-85qx-mfpj-cvj4", - "modified": "2025-04-03T18:30:53Z", + "modified": "2025-06-05T15:31:21Z", "published": "2025-01-26T06:30:48Z", "aliases": [ "CVE-2024-10628" diff --git a/advisories/unreviewed/2025/01/GHSA-m7jq-35x5-2p74/GHSA-m7jq-35x5-2p74.json b/advisories/unreviewed/2025/01/GHSA-m7jq-35x5-2p74/GHSA-m7jq-35x5-2p74.json index ea3086c397d..8612805b035 100644 --- a/advisories/unreviewed/2025/01/GHSA-m7jq-35x5-2p74/GHSA-m7jq-35x5-2p74.json +++ b/advisories/unreviewed/2025/01/GHSA-m7jq-35x5-2p74/GHSA-m7jq-35x5-2p74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7jq-35x5-2p74", - "modified": "2025-01-09T12:30:56Z", + "modified": "2025-06-05T15:31:20Z", "published": "2025-01-09T12:30:56Z", "aliases": [ "CVE-2024-6155" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/04/GHSA-22wj-vp2m-rxhc/GHSA-22wj-vp2m-rxhc.json b/advisories/unreviewed/2025/04/GHSA-22wj-vp2m-rxhc/GHSA-22wj-vp2m-rxhc.json index 86a58f70791..a02f2c3ac30 100644 --- a/advisories/unreviewed/2025/04/GHSA-22wj-vp2m-rxhc/GHSA-22wj-vp2m-rxhc.json +++ b/advisories/unreviewed/2025/04/GHSA-22wj-vp2m-rxhc/GHSA-22wj-vp2m-rxhc.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-23" + "CWE-23", + "CWE-704" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2v5h-r74h-52p7/GHSA-2v5h-r74h-52p7.json b/advisories/unreviewed/2025/05/GHSA-2v5h-r74h-52p7/GHSA-2v5h-r74h-52p7.json index b8df0561b1d..6f5079877eb 100644 --- a/advisories/unreviewed/2025/05/GHSA-2v5h-r74h-52p7/GHSA-2v5h-r74h-52p7.json +++ b/advisories/unreviewed/2025/05/GHSA-2v5h-r74h-52p7/GHSA-2v5h-r74h-52p7.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json b/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json index e3e77c93d57..3346fd2e7d1 100644 --- a/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json +++ b/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-3g6q-j56q-qw54/GHSA-3g6q-j56q-qw54.json b/advisories/unreviewed/2025/05/GHSA-3g6q-j56q-qw54/GHSA-3g6q-j56q-qw54.json index f04cf6c38fb..36bf8d57b70 100644 --- a/advisories/unreviewed/2025/05/GHSA-3g6q-j56q-qw54/GHSA-3g6q-j56q-qw54.json +++ b/advisories/unreviewed/2025/05/GHSA-3g6q-j56q-qw54/GHSA-3g6q-j56q-qw54.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3g6q-j56q-qw54", - "modified": "2025-05-08T09:30:23Z", + "modified": "2025-06-05T15:31:22Z", "published": "2025-05-08T09:30:23Z", "aliases": [ "CVE-2025-37800" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: fix potential NULL pointer dereference in dev_uevent()\n\nIf userspace reads \"uevent\" device attribute at the same time as another\nthreads unbinds the device from its driver, change to dev->driver from a\nvalid pointer to NULL may result in crash. Fix this by using READ_ONCE()\nwhen fetching the pointer, and take bus' drivers klist lock to make sure\ndriver instance will not disappear while we access it.\n\nUse WRITE_ONCE() when setting the driver pointer to ensure there is no\ntearing.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T07:15:50Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3gjx-hg47-fq76/GHSA-3gjx-hg47-fq76.json b/advisories/unreviewed/2025/05/GHSA-3gjx-hg47-fq76/GHSA-3gjx-hg47-fq76.json index d25e2ae0f10..42564021296 100644 --- a/advisories/unreviewed/2025/05/GHSA-3gjx-hg47-fq76/GHSA-3gjx-hg47-fq76.json +++ b/advisories/unreviewed/2025/05/GHSA-3gjx-hg47-fq76/GHSA-3gjx-hg47-fq76.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3j4j-xg7r-jh7c/GHSA-3j4j-xg7r-jh7c.json b/advisories/unreviewed/2025/05/GHSA-3j4j-xg7r-jh7c/GHSA-3j4j-xg7r-jh7c.json index b7eb92415dc..8d3f80074bc 100644 --- a/advisories/unreviewed/2025/05/GHSA-3j4j-xg7r-jh7c/GHSA-3j4j-xg7r-jh7c.json +++ b/advisories/unreviewed/2025/05/GHSA-3j4j-xg7r-jh7c/GHSA-3j4j-xg7r-jh7c.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j4j-xg7r-jh7c", - "modified": "2025-05-08T09:30:25Z", + "modified": "2025-06-05T15:31:23Z", "published": "2025-05-08T09:30:25Z", "aliases": [ "CVE-2025-1253" ], "details": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 4.5 before 6.1.2.23.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-3mh5-w32f-4q7c/GHSA-3mh5-w32f-4q7c.json b/advisories/unreviewed/2025/05/GHSA-3mh5-w32f-4q7c/GHSA-3mh5-w32f-4q7c.json index 96982612d3e..9c59e7e8bd1 100644 --- a/advisories/unreviewed/2025/05/GHSA-3mh5-w32f-4q7c/GHSA-3mh5-w32f-4q7c.json +++ b/advisories/unreviewed/2025/05/GHSA-3mh5-w32f-4q7c/GHSA-3mh5-w32f-4q7c.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json b/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json index 2b172e14d1d..bb6907adcb8 100644 --- a/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json +++ b/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-42fq-x79v-5vv5/GHSA-42fq-x79v-5vv5.json b/advisories/unreviewed/2025/05/GHSA-42fq-x79v-5vv5/GHSA-42fq-x79v-5vv5.json index ae3c64d1179..0136be68ee3 100644 --- a/advisories/unreviewed/2025/05/GHSA-42fq-x79v-5vv5/GHSA-42fq-x79v-5vv5.json +++ b/advisories/unreviewed/2025/05/GHSA-42fq-x79v-5vv5/GHSA-42fq-x79v-5vv5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-42fq-x79v-5vv5", - "modified": "2025-05-08T09:30:23Z", + "modified": "2025-06-05T15:31:23Z", "published": "2025-05-08T09:30:23Z", "aliases": [ "CVE-2025-37803" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudmabuf: fix a buf size overflow issue during udmabuf creation\n\nby casting size_limit_mb to u64 when calculate pglimit.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T07:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4c33-h9j5-vmhj/GHSA-4c33-h9j5-vmhj.json b/advisories/unreviewed/2025/05/GHSA-4c33-h9j5-vmhj/GHSA-4c33-h9j5-vmhj.json index 586d3791fcc..92ff0d70160 100644 --- a/advisories/unreviewed/2025/05/GHSA-4c33-h9j5-vmhj/GHSA-4c33-h9j5-vmhj.json +++ b/advisories/unreviewed/2025/05/GHSA-4c33-h9j5-vmhj/GHSA-4c33-h9j5-vmhj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-56c5-8gc7-wj67/GHSA-56c5-8gc7-wj67.json b/advisories/unreviewed/2025/05/GHSA-56c5-8gc7-wj67/GHSA-56c5-8gc7-wj67.json index 286d73e18a9..d7eaa4673d8 100644 --- a/advisories/unreviewed/2025/05/GHSA-56c5-8gc7-wj67/GHSA-56c5-8gc7-wj67.json +++ b/advisories/unreviewed/2025/05/GHSA-56c5-8gc7-wj67/GHSA-56c5-8gc7-wj67.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-56c5-8gc7-wj67", - "modified": "2025-05-08T09:30:23Z", + "modified": "2025-06-05T15:31:23Z", "published": "2025-05-08T09:30:23Z", "aliases": [ "CVE-2025-37802" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix WARNING \"do not call blocking ops when !TASK_RUNNING\"\n\nwait_event_timeout() will set the state of the current\ntask to TASK_UNINTERRUPTIBLE, before doing the condition check. This\nmeans that ksmbd_durable_scavenger_alive() will try to acquire the mutex\nwhile already in a sleeping state. The scheduler warns us by giving\nthe following warning:\n\ndo not call blocking ops when !TASK_RUNNING; state=2 set at\n [<0000000061515a6f>] prepare_to_wait_event+0x9f/0x6c0\nWARNING: CPU: 2 PID: 4147 at kernel/sched/core.c:10099 __might_sleep+0x12f/0x160\n\nmutex lock is not needed in ksmbd_durable_scavenger_alive().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T07:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6g5q-gcp5-pcwq/GHSA-6g5q-gcp5-pcwq.json b/advisories/unreviewed/2025/05/GHSA-6g5q-gcp5-pcwq/GHSA-6g5q-gcp5-pcwq.json index 853ca3d7798..c7217b06cee 100644 --- a/advisories/unreviewed/2025/05/GHSA-6g5q-gcp5-pcwq/GHSA-6g5q-gcp5-pcwq.json +++ b/advisories/unreviewed/2025/05/GHSA-6g5q-gcp5-pcwq/GHSA-6g5q-gcp5-pcwq.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7mcp-f35c-w4mw/GHSA-7mcp-f35c-w4mw.json b/advisories/unreviewed/2025/05/GHSA-7mcp-f35c-w4mw/GHSA-7mcp-f35c-w4mw.json index ca21bc49c07..dda6c98c553 100644 --- a/advisories/unreviewed/2025/05/GHSA-7mcp-f35c-w4mw/GHSA-7mcp-f35c-w4mw.json +++ b/advisories/unreviewed/2025/05/GHSA-7mcp-f35c-w4mw/GHSA-7mcp-f35c-w4mw.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7mcp-f35c-w4mw", - "modified": "2025-05-08T09:30:25Z", + "modified": "2025-06-05T15:31:23Z", "published": "2025-05-08T09:30:25Z", "aliases": [ "CVE-2025-1252" ], "details": "Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 4.4 before 6.1.2.23.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -26,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json b/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json index ad4111a47d8..09fc87eed69 100644 --- a/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json +++ b/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-ccqq-2fg9-r782/GHSA-ccqq-2fg9-r782.json b/advisories/unreviewed/2025/05/GHSA-ccqq-2fg9-r782/GHSA-ccqq-2fg9-r782.json index 7002abefb87..5175c1a6505 100644 --- a/advisories/unreviewed/2025/05/GHSA-ccqq-2fg9-r782/GHSA-ccqq-2fg9-r782.json +++ b/advisories/unreviewed/2025/05/GHSA-ccqq-2fg9-r782/GHSA-ccqq-2fg9-r782.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json b/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json index 5b26bdfd239..a4961d1c696 100644 --- a/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json +++ b/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-f7g9-mhw7-w4wj/GHSA-f7g9-mhw7-w4wj.json b/advisories/unreviewed/2025/05/GHSA-f7g9-mhw7-w4wj/GHSA-f7g9-mhw7-w4wj.json index a8fbfe91353..cedf871b569 100644 --- a/advisories/unreviewed/2025/05/GHSA-f7g9-mhw7-w4wj/GHSA-f7g9-mhw7-w4wj.json +++ b/advisories/unreviewed/2025/05/GHSA-f7g9-mhw7-w4wj/GHSA-f7g9-mhw7-w4wj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-fg4q-8p94-mj4j/GHSA-fg4q-8p94-mj4j.json b/advisories/unreviewed/2025/05/GHSA-fg4q-8p94-mj4j/GHSA-fg4q-8p94-mj4j.json index dc5a50200ca..0fae8e903a9 100644 --- a/advisories/unreviewed/2025/05/GHSA-fg4q-8p94-mj4j/GHSA-fg4q-8p94-mj4j.json +++ b/advisories/unreviewed/2025/05/GHSA-fg4q-8p94-mj4j/GHSA-fg4q-8p94-mj4j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg4q-8p94-mj4j", - "modified": "2025-05-08T09:30:24Z", + "modified": "2025-06-05T15:31:23Z", "published": "2025-05-08T09:30:23Z", "aliases": [ "CVE-2025-37805" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsound/virtio: Fix cancel_sync warnings on uninitialized work_structs\n\nBetty reported hitting the following warning:\n\n[ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c:4182\n...\n[ 8.713282][ T221] Call trace:\n[ 8.713365][ T221] __flush_work+0x8d0/0x914\n[ 8.713468][ T221] __cancel_work_sync+0xac/0xfc\n[ 8.713570][ T221] cancel_work_sync+0x24/0x34\n[ 8.713667][ T221] virtsnd_remove+0xa8/0xf8 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.713868][ T221] virtsnd_probe+0x48c/0x664 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.714035][ T221] virtio_dev_probe+0x28c/0x390\n[ 8.714139][ T221] really_probe+0x1bc/0x4c8\n...\n\nIt seems we're hitting the error path in virtsnd_probe(), which\ntriggers a virtsnd_remove() which iterates over the substreams\ncalling cancel_work_sync() on the elapsed_period work_struct.\n\nLooking at the code, from earlier in:\nvirtsnd_probe()->virtsnd_build_devs()->virtsnd_pcm_parse_cfg()\n\nWe set snd->nsubstreams, allocate the snd->substreams, and if\nwe then hit an error on the info allocation or something in\nvirtsnd_ctl_query_info() fails, we will exit without having\ninitialized the elapsed_period work_struct.\n\nWhen that error path unwinds we then call virtsnd_remove()\nwhich as long as the substreams array is allocated, will iterate\nthrough calling cancel_work_sync() on the uninitialized work\nstruct hitting this warning.\n\nTakashi Iwai suggested this fix, which initializes the substreams\nstructure right after allocation, so that if we hit the error\npaths we avoid trying to cleanup uninitialized data.\n\nNote: I have not yet managed to reproduce the issue myself, so\nthis patch has had limited testing.\n\nFeedback or thoughts would be appreciated!", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T07:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-g8jq-rx5f-94q7/GHSA-g8jq-rx5f-94q7.json b/advisories/unreviewed/2025/05/GHSA-g8jq-rx5f-94q7/GHSA-g8jq-rx5f-94q7.json index a715cd22186..235d2877a1e 100644 --- a/advisories/unreviewed/2025/05/GHSA-g8jq-rx5f-94q7/GHSA-g8jq-rx5f-94q7.json +++ b/advisories/unreviewed/2025/05/GHSA-g8jq-rx5f-94q7/GHSA-g8jq-rx5f-94q7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g8jq-rx5f-94q7", - "modified": "2025-05-22T15:34:49Z", + "modified": "2025-06-05T15:31:26Z", "published": "2025-05-22T15:34:49Z", "aliases": [ "CVE-2025-3945" diff --git a/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json b/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json index 017ce7a4246..37a2d6cbb76 100644 --- a/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json +++ b/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-j83p-cqxw-j383/GHSA-j83p-cqxw-j383.json b/advisories/unreviewed/2025/05/GHSA-j83p-cqxw-j383/GHSA-j83p-cqxw-j383.json index cee47d8ebbb..f3fa8a17639 100644 --- a/advisories/unreviewed/2025/05/GHSA-j83p-cqxw-j383/GHSA-j83p-cqxw-j383.json +++ b/advisories/unreviewed/2025/05/GHSA-j83p-cqxw-j383/GHSA-j83p-cqxw-j383.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jhcc-gwm2-46v7/GHSA-jhcc-gwm2-46v7.json b/advisories/unreviewed/2025/05/GHSA-jhcc-gwm2-46v7/GHSA-jhcc-gwm2-46v7.json index 07ff98d4fde..b44ed19b7b1 100644 --- a/advisories/unreviewed/2025/05/GHSA-jhcc-gwm2-46v7/GHSA-jhcc-gwm2-46v7.json +++ b/advisories/unreviewed/2025/05/GHSA-jhcc-gwm2-46v7/GHSA-jhcc-gwm2-46v7.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-302" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/05/GHSA-jxcf-8cjj-rm75/GHSA-jxcf-8cjj-rm75.json b/advisories/unreviewed/2025/05/GHSA-jxcf-8cjj-rm75/GHSA-jxcf-8cjj-rm75.json index 06dbebb4013..1f7f9519447 100644 --- a/advisories/unreviewed/2025/05/GHSA-jxcf-8cjj-rm75/GHSA-jxcf-8cjj-rm75.json +++ b/advisories/unreviewed/2025/05/GHSA-jxcf-8cjj-rm75/GHSA-jxcf-8cjj-rm75.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json b/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json index acd67d58e6b..5f357c85918 100644 --- a/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json +++ b/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json b/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json index 888cf08dd3e..fd273d30505 100644 --- a/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json +++ b/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json b/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json index df9c2d8f80d..9107782768c 100644 --- a/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json +++ b/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-qmpq-8rmr-c5hm/GHSA-qmpq-8rmr-c5hm.json b/advisories/unreviewed/2025/05/GHSA-qmpq-8rmr-c5hm/GHSA-qmpq-8rmr-c5hm.json index a743e1ddf04..fbd03772858 100644 --- a/advisories/unreviewed/2025/05/GHSA-qmpq-8rmr-c5hm/GHSA-qmpq-8rmr-c5hm.json +++ b/advisories/unreviewed/2025/05/GHSA-qmpq-8rmr-c5hm/GHSA-qmpq-8rmr-c5hm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmpq-8rmr-c5hm", - "modified": "2025-05-08T09:30:25Z", + "modified": "2025-06-05T15:31:23Z", "published": "2025-05-08T09:30:25Z", "aliases": [ "CVE-2025-1254" ], "details": "Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers, Overflow Buffers.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.0.0 before 6.1.2.23.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -26,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-r7vp-rjp7-f82g/GHSA-r7vp-rjp7-f82g.json b/advisories/unreviewed/2025/05/GHSA-r7vp-rjp7-f82g/GHSA-r7vp-rjp7-f82g.json index fe8cd5079e8..f459c7c22e7 100644 --- a/advisories/unreviewed/2025/05/GHSA-r7vp-rjp7-f82g/GHSA-r7vp-rjp7-f82g.json +++ b/advisories/unreviewed/2025/05/GHSA-r7vp-rjp7-f82g/GHSA-r7vp-rjp7-f82g.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rqxv-qh6g-hx7g/GHSA-rqxv-qh6g-hx7g.json b/advisories/unreviewed/2025/05/GHSA-rqxv-qh6g-hx7g/GHSA-rqxv-qh6g-hx7g.json index 775ff4e98db..121b1cbce49 100644 --- a/advisories/unreviewed/2025/05/GHSA-rqxv-qh6g-hx7g/GHSA-rqxv-qh6g-hx7g.json +++ b/advisories/unreviewed/2025/05/GHSA-rqxv-qh6g-hx7g/GHSA-rqxv-qh6g-hx7g.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rvvg-x7w9-2mmq/GHSA-rvvg-x7w9-2mmq.json b/advisories/unreviewed/2025/05/GHSA-rvvg-x7w9-2mmq/GHSA-rvvg-x7w9-2mmq.json index 4f4c5d75a01..c5e65b1b608 100644 --- a/advisories/unreviewed/2025/05/GHSA-rvvg-x7w9-2mmq/GHSA-rvvg-x7w9-2mmq.json +++ b/advisories/unreviewed/2025/05/GHSA-rvvg-x7w9-2mmq/GHSA-rvvg-x7w9-2mmq.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v757-732c-m4r4/GHSA-v757-732c-m4r4.json b/advisories/unreviewed/2025/05/GHSA-v757-732c-m4r4/GHSA-v757-732c-m4r4.json index 5bc01bf37b4..6ea36f76408 100644 --- a/advisories/unreviewed/2025/05/GHSA-v757-732c-m4r4/GHSA-v757-732c-m4r4.json +++ b/advisories/unreviewed/2025/05/GHSA-v757-732c-m4r4/GHSA-v757-732c-m4r4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vp37-f5jx-gpcx/GHSA-vp37-f5jx-gpcx.json b/advisories/unreviewed/2025/05/GHSA-vp37-f5jx-gpcx/GHSA-vp37-f5jx-gpcx.json index b829f561650..fc87b0d317d 100644 --- a/advisories/unreviewed/2025/05/GHSA-vp37-f5jx-gpcx/GHSA-vp37-f5jx-gpcx.json +++ b/advisories/unreviewed/2025/05/GHSA-vp37-f5jx-gpcx/GHSA-vp37-f5jx-gpcx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vp37-f5jx-gpcx", - "modified": "2025-05-08T09:30:23Z", + "modified": "2025-06-05T15:31:22Z", "published": "2025-05-08T09:30:23Z", "aliases": [ "CVE-2025-37801" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-imx: Add check for spi_imx_setupxfer()\n\nAdd check for the return value of spi_imx_setupxfer().\nspi_imx->rx and spi_imx->tx function pointer can be NULL when\nspi_imx_setupxfer() return error, and make NULL pointer dereference.\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Call trace:\n 0x0\n spi_imx_pio_transfer+0x50/0xd8\n spi_imx_transfer_one+0x18c/0x858\n spi_transfer_one_message+0x43c/0x790\n __spi_pump_transfer_message+0x238/0x5d4\n __spi_sync+0x2b0/0x454\n spi_write_then_read+0x11c/0x200", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-08T07:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wgxj-j7f6-p388/GHSA-wgxj-j7f6-p388.json b/advisories/unreviewed/2025/05/GHSA-wgxj-j7f6-p388/GHSA-wgxj-j7f6-p388.json index d15c09261fa..a5ec99a04ec 100644 --- a/advisories/unreviewed/2025/05/GHSA-wgxj-j7f6-p388/GHSA-wgxj-j7f6-p388.json +++ b/advisories/unreviewed/2025/05/GHSA-wgxj-j7f6-p388/GHSA-wgxj-j7f6-p388.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json b/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json index 081521dc94a..e6bdfd3a8e8 100644 --- a/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json +++ b/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-xpvq-w32j-6px4/GHSA-xpvq-w32j-6px4.json b/advisories/unreviewed/2025/05/GHSA-xpvq-w32j-6px4/GHSA-xpvq-w32j-6px4.json index b0c16592657..66659b1ef8f 100644 --- a/advisories/unreviewed/2025/05/GHSA-xpvq-w32j-6px4/GHSA-xpvq-w32j-6px4.json +++ b/advisories/unreviewed/2025/05/GHSA-xpvq-w32j-6px4/GHSA-xpvq-w32j-6px4.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-3q79-wmhj-39pr/GHSA-3q79-wmhj-39pr.json b/advisories/unreviewed/2025/06/GHSA-3q79-wmhj-39pr/GHSA-3q79-wmhj-39pr.json index 90f43eb2c52..440c94ed5ff 100644 --- a/advisories/unreviewed/2025/06/GHSA-3q79-wmhj-39pr/GHSA-3q79-wmhj-39pr.json +++ b/advisories/unreviewed/2025/06/GHSA-3q79-wmhj-39pr/GHSA-3q79-wmhj-39pr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-3rhc-hj98-5mpj/GHSA-3rhc-hj98-5mpj.json b/advisories/unreviewed/2025/06/GHSA-3rhc-hj98-5mpj/GHSA-3rhc-hj98-5mpj.json new file mode 100644 index 00000000000..a8dc1cf10b4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3rhc-hj98-5mpj/GHSA-3rhc-hj98-5mpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rhc-hj98-5mpj", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-3768" + ], + "details": "Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3768" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json b/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json index f69f197a1db..e45de13e773 100644 --- a/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json +++ b/advisories/unreviewed/2025/06/GHSA-4g4g-fqw4-prp2/GHSA-4g4g-fqw4-prp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g4g-fqw4-prp2", - "modified": "2025-06-03T21:30:36Z", + "modified": "2025-06-05T15:31:30Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4138" diff --git a/advisories/unreviewed/2025/06/GHSA-4rgj-78j5-635j/GHSA-4rgj-78j5-635j.json b/advisories/unreviewed/2025/06/GHSA-4rgj-78j5-635j/GHSA-4rgj-78j5-635j.json index 776fff5da0f..dd31ae14cec 100644 --- a/advisories/unreviewed/2025/06/GHSA-4rgj-78j5-635j/GHSA-4rgj-78j5-635j.json +++ b/advisories/unreviewed/2025/06/GHSA-4rgj-78j5-635j/GHSA-4rgj-78j5-635j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json b/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json index e1625d57001..6c8babc0477 100644 --- a/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json +++ b/advisories/unreviewed/2025/06/GHSA-68pj-xrp5-vccj/GHSA-68pj-xrp5-vccj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68pj-xrp5-vccj", - "modified": "2025-06-03T21:30:36Z", + "modified": "2025-06-05T15:31:31Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4330" diff --git a/advisories/unreviewed/2025/06/GHSA-6p39-gq6w-rwhx/GHSA-6p39-gq6w-rwhx.json b/advisories/unreviewed/2025/06/GHSA-6p39-gq6w-rwhx/GHSA-6p39-gq6w-rwhx.json index 9de49e67fa9..0f9ab215687 100644 --- a/advisories/unreviewed/2025/06/GHSA-6p39-gq6w-rwhx/GHSA-6p39-gq6w-rwhx.json +++ b/advisories/unreviewed/2025/06/GHSA-6p39-gq6w-rwhx/GHSA-6p39-gq6w-rwhx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json b/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json index e9cf54ccdc1..4a8d37c0df4 100644 --- a/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json +++ b/advisories/unreviewed/2025/06/GHSA-6r6c-684h-9j7p/GHSA-6r6c-684h-9j7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r6c-684h-9j7p", - "modified": "2025-06-03T21:30:37Z", + "modified": "2025-06-05T15:31:31Z", "published": "2025-06-03T15:31:25Z", "aliases": [ "CVE-2025-4517" diff --git a/advisories/unreviewed/2025/06/GHSA-6vfv-v5v8-qx7q/GHSA-6vfv-v5v8-qx7q.json b/advisories/unreviewed/2025/06/GHSA-6vfv-v5v8-qx7q/GHSA-6vfv-v5v8-qx7q.json new file mode 100644 index 00000000000..7c6f7daf1aa --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6vfv-v5v8-qx7q/GHSA-6vfv-v5v8-qx7q.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vfv-v5v8-qx7q", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-27445" + ], + "details": "A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused by insufficient sanitization of user-supplied input in file path parameters, allowing attackers to exploit directory traversal sequences (e.g., ../) to access sensitive files", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27445" + }, + { + "type": "WEB", + "url": "https://rsjoomla.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-867v-2jwx-jqmx/GHSA-867v-2jwx-jqmx.json b/advisories/unreviewed/2025/06/GHSA-867v-2jwx-jqmx/GHSA-867v-2jwx-jqmx.json new file mode 100644 index 00000000000..779484b4a5c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-867v-2jwx-jqmx/GHSA-867v-2jwx-jqmx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-867v-2jwx-jqmx", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-5658" + ], + "details": "A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/updatecomplaint.php. The manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5658" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/47" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311148" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311148" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589979" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json b/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json index 0a0e088d4ff..f35338ccc27 100644 --- a/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json +++ b/advisories/unreviewed/2025/06/GHSA-cvg9-q978-4569/GHSA-cvg9-q978-4569.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cvg9-q978-4569", - "modified": "2025-06-05T12:31:09Z", + "modified": "2025-06-05T15:31:32Z", "published": "2025-06-05T12:31:09Z", "aliases": [ "CVE-2011-10007" ], "details": "File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename.\n\nA file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to provide the MODE parameter to `open()`, turning the filename into a command to be executed.\n\nExample:\n\n$ mkdir /tmp/poc; echo > \"/tmp/poc/|id\"\n$ perl -MFile::Find::Rule \\\n    -E 'File::Find::Rule->grep(\"foo\")->in(\"/tmp/poc\")'\nuid=1000(user) gid=1000(user) groups=1000(user),100(users)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -35,7 +40,7 @@ "cwe_ids": [ "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-05T12:15:22Z" diff --git a/advisories/unreviewed/2025/06/GHSA-cvrx-7jm4-3pg5/GHSA-cvrx-7jm4-3pg5.json b/advisories/unreviewed/2025/06/GHSA-cvrx-7jm4-3pg5/GHSA-cvrx-7jm4-3pg5.json new file mode 100644 index 00000000000..13fa643f4a0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cvrx-7jm4-3pg5/GHSA-cvrx-7jm4-3pg5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvrx-7jm4-3pg5", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-5659" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnerability is an unknown functionality of the file /user/profile.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5659" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/48" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311149" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311149" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589980" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g9c9-hr7f-cr62/GHSA-g9c9-hr7f-cr62.json b/advisories/unreviewed/2025/06/GHSA-g9c9-hr7f-cr62/GHSA-g9c9-hr7f-cr62.json new file mode 100644 index 00000000000..4c41e44f436 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-g9c9-hr7f-cr62/GHSA-g9c9-hr7f-cr62.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9c9-hr7f-cr62", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-27753" + ], + "details": "A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use of unescaped user-supplied parameters in SQL queries within the dashboard component. This allows an authenticated attacker to inject malicious SQL code through unsanitized input fields, which are used directly in SQL queries. Exploiting this flaw can lead to unauthorized database access, data leakage, or modification of records.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27753" + }, + { + "type": "WEB", + "url": "https://rsjoomla.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gcgr-4v7p-g97q/GHSA-gcgr-4v7p-g97q.json b/advisories/unreviewed/2025/06/GHSA-gcgr-4v7p-g97q/GHSA-gcgr-4v7p-g97q.json new file mode 100644 index 00000000000..f4ba62b9955 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gcgr-4v7p-g97q/GHSA-gcgr-4v7p-g97q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcgr-4v7p-g97q", + "modified": "2025-06-05T15:31:33Z", + "published": "2025-06-05T15:31:33Z", + "aliases": [ + "CVE-2025-5661" + ], + "details": "A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part of the file /save-settings.php of the component Setting Handler. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5661" + }, + { + "type": "WEB", + "url": "https://github.com/tuooo/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311151" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311151" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hp3h-rxwj-jc56/GHSA-hp3h-rxwj-jc56.json b/advisories/unreviewed/2025/06/GHSA-hp3h-rxwj-jc56/GHSA-hp3h-rxwj-jc56.json new file mode 100644 index 00000000000..ab42362994f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hp3h-rxwj-jc56/GHSA-hp3h-rxwj-jc56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp3h-rxwj-jc56", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-27754" + ], + "details": "A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27754" + }, + { + "type": "WEB", + "url": "https://rsjoomla.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hrhf-c3vg-c6p2/GHSA-hrhf-c3vg-c6p2.json b/advisories/unreviewed/2025/06/GHSA-hrhf-c3vg-c6p2/GHSA-hrhf-c3vg-c6p2.json new file mode 100644 index 00000000000..26ca95422dd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hrhf-c3vg-c6p2/GHSA-hrhf-c3vg-c6p2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrhf-c3vg-c6p2", + "modified": "2025-06-05T15:31:33Z", + "published": "2025-06-05T15:31:33Z", + "aliases": [ + "CVE-2025-5664" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component RESTART Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5664" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-e18bb6a8ab3c9991cf4de291efced47f926725e0d76b9d0cfb0c3a1835f99ce3.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311153" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311153" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.587021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j94f-r4m9-43wp/GHSA-j94f-r4m9-43wp.json b/advisories/unreviewed/2025/06/GHSA-j94f-r4m9-43wp/GHSA-j94f-r4m9-43wp.json new file mode 100644 index 00000000000..5d2a1aec511 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j94f-r4m9-43wp/GHSA-j94f-r4m9-43wp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j94f-r4m9-43wp", + "modified": "2025-06-05T15:31:33Z", + "published": "2025-06-05T15:31:33Z", + "aliases": [ + "CVE-2025-5663" + ], + "details": "A vulnerability has been found in PHPGurukul Auto Taxi Stand Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search-autoortaxi.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5663" + }, + { + "type": "WEB", + "url": "https://github.com/Pjwww13447/pjwww/issues/20" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311152" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311152" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590055" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jq92-hhc7-45w7/GHSA-jq92-hhc7-45w7.json b/advisories/unreviewed/2025/06/GHSA-jq92-hhc7-45w7/GHSA-jq92-hhc7-45w7.json new file mode 100644 index 00000000000..bd27765c8dc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jq92-hhc7-45w7/GHSA-jq92-hhc7-45w7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq92-hhc7-45w7", + "modified": "2025-06-05T15:31:33Z", + "published": "2025-06-05T15:31:33Z", + "aliases": [ + "CVE-2025-5382" + ], + "details": "Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5382" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pq63-hp83-c5hf/GHSA-pq63-hp83-c5hf.json b/advisories/unreviewed/2025/06/GHSA-pq63-hp83-c5hf/GHSA-pq63-hp83-c5hf.json new file mode 100644 index 00000000000..d3fde791b07 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pq63-hp83-c5hf/GHSA-pq63-hp83-c5hf.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq63-hp83-c5hf", + "modified": "2025-06-05T15:31:34Z", + "published": "2025-06-05T15:31:33Z", + "aliases": [ + "CVE-2025-5665" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component XCWD Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5665" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-e4f6f2a0b9cd918ca9c6dbdb1098d674b121997846a06f423d0023084f7cf3df.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311154" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311154" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.587024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pww7-j9v6-xc6j/GHSA-pww7-j9v6-xc6j.json b/advisories/unreviewed/2025/06/GHSA-pww7-j9v6-xc6j/GHSA-pww7-j9v6-xc6j.json new file mode 100644 index 00000000000..e71fadfbf7e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pww7-j9v6-xc6j/GHSA-pww7-j9v6-xc6j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pww7-j9v6-xc6j", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-47827" + ], + "details": "In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47827" + }, + { + "type": "WEB", + "url": "https://github.com/Zedeldi/CVE-2025-47827" + }, + { + "type": "WEB", + "url": "https://github.com/Zedeldi/igelfs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q387-9xqr-fhhg/GHSA-q387-9xqr-fhhg.json b/advisories/unreviewed/2025/06/GHSA-q387-9xqr-fhhg/GHSA-q387-9xqr-fhhg.json new file mode 100644 index 00000000000..6a9b8b03495 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q387-9xqr-fhhg/GHSA-q387-9xqr-fhhg.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q387-9xqr-fhhg", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-30084" + ], + "details": "A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code into text fields or other input points, which is subsequently executed in the browser of any user who clicks on the crafted text in the dashboard.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30084" + }, + { + "type": "WEB", + "url": "https://rsjoomla.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vx5h-76cf-gj47/GHSA-vx5h-76cf-gj47.json b/advisories/unreviewed/2025/06/GHSA-vx5h-76cf-gj47/GHSA-vx5h-76cf-gj47.json index c5a0c526462..3b14c15264e 100644 --- a/advisories/unreviewed/2025/06/GHSA-vx5h-76cf-gj47/GHSA-vx5h-76cf-gj47.json +++ b/advisories/unreviewed/2025/06/GHSA-vx5h-76cf-gj47/GHSA-vx5h-76cf-gj47.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-xjfj-m5rc-8ffm/GHSA-xjfj-m5rc-8ffm.json b/advisories/unreviewed/2025/06/GHSA-xjfj-m5rc-8ffm/GHSA-xjfj-m5rc-8ffm.json new file mode 100644 index 00000000000..ba5cef324d0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xjfj-m5rc-8ffm/GHSA-xjfj-m5rc-8ffm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjfj-m5rc-8ffm", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-0691" + ], + "details": "Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the \"Edit permission\" permission by bypassing the client side validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0691" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xqh6-qrw4-qhwj/GHSA-xqh6-qrw4-qhwj.json b/advisories/unreviewed/2025/06/GHSA-xqh6-qrw4-qhwj/GHSA-xqh6-qrw4-qhwj.json new file mode 100644 index 00000000000..2f2aa08e677 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xqh6-qrw4-qhwj/GHSA-xqh6-qrw4-qhwj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqh6-qrw4-qhwj", + "modified": "2025-06-05T15:31:32Z", + "published": "2025-06-05T15:31:32Z", + "aliases": [ + "CVE-2025-5660" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affected by this issue is some unknown functionality of the file /user/register-complaint.php. The manipulation of the argument noc leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5660" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/49" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311150" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311150" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.589981" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-05T13:15:22Z" + } +} \ No newline at end of file