Skip to content

Commit cbed092

Browse files
Advisory Database Sync
1 parent faa2990 commit cbed092

59 files changed

Lines changed: 1147 additions & 97 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/unreviewed/2025/06/GHSA-wppx-2c2r-43hc/GHSA-wppx-2c2r-43hc.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-wppx-2c2r-43hc",
4-
"modified": "2025-09-02T21:30:56Z",
4+
"modified": "2026-03-25T15:31:23Z",
55
"published": "2025-06-20T21:32:06Z",
66
"aliases": [
77
"CVE-2025-6193"
@@ -23,6 +23,10 @@
2323
"type": "WEB",
2424
"url": "https://github.com/trustyai-explainability/trustyai-service-operator/pull/504"
2525
},
26+
{
27+
"type": "WEB",
28+
"url": "https://access.redhat.com/errata/RHSA-2026:5807"
29+
},
2630
{
2731
"type": "WEB",
2832
"url": "https://access.redhat.com/security/cve/CVE-2025-6193"

advisories/unreviewed/2025/09/GHSA-mj23-mw6g-p34x/GHSA-mj23-mw6g-p34x.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-mj23-mw6g-p34x",
4-
"modified": "2025-09-25T15:30:23Z",
4+
"modified": "2026-03-25T15:31:23Z",
55
"published": "2025-09-25T15:30:23Z",
66
"aliases": [
77
"CVE-2025-10947"

advisories/unreviewed/2025/10/GHSA-57c3-6898-289j/GHSA-57c3-6898-289j.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-57c3-6898-289j",
4-
"modified": "2025-10-05T06:30:14Z",
4+
"modified": "2026-03-25T15:31:24Z",
55
"published": "2025-10-05T06:30:14Z",
66
"aliases": [
77
"CVE-2025-11282"
@@ -31,6 +31,10 @@
3131
"type": "WEB",
3232
"url": "https://gist.github.com/0xHamy/c2a81f2d1c779c513fa3db6f3ad24544#steps-to-reproduce"
3333
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/frappe/lms"
37+
},
3438
{
3539
"type": "WEB",
3640
"url": "https://vuldb.com/?ctiid.327016"

advisories/unreviewed/2026/02/GHSA-cc7r-67vc-28jh/GHSA-cc7r-67vc-28jh.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,17 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-cc7r-67vc-28jh",
4-
"modified": "2026-02-03T00:30:19Z",
4+
"modified": "2026-03-25T15:31:24Z",
55
"published": "2026-02-03T00:30:19Z",
66
"aliases": [
77
"CVE-2025-61642"
88
],
99
"details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php.\n\nThis issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.",
1010
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
14+
},
1115
{
1216
"type": "CVSS_V4",
1317
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"

advisories/unreviewed/2026/02/GHSA-jrq3-c447-h584/GHSA-jrq3-c447-h584.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,17 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-jrq3-c447-h584",
4-
"modified": "2026-02-03T03:30:26Z",
4+
"modified": "2026-03-25T15:31:24Z",
55
"published": "2026-02-03T03:30:26Z",
66
"aliases": [
77
"CVE-2025-11261"
88
],
99
"details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Language/mediawiki.Language.Js.\n\nThis issue affects MediaWiki: from * before 1.39.15, 1.43.5, 1.44.2.",
1010
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
14+
},
1115
{
1216
"type": "CVSS_V4",
1317
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"

advisories/unreviewed/2026/02/GHSA-pw42-76j9-fcp3/GHSA-pw42-76j9-fcp3.json

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,17 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-pw42-76j9-fcp3",
4-
"modified": "2026-02-03T00:30:19Z",
4+
"modified": "2026-03-25T15:31:24Z",
55
"published": "2026-02-03T00:30:19Z",
66
"aliases": [
77
"CVE-2025-61643"
88
],
99
"details": "Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchanges/RecentChangeRCFeedNotifier.Php.\n\nThis issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.",
1010
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
14+
},
1115
{
1216
"type": "CVSS_V4",
1317
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green"
@@ -25,7 +29,9 @@
2529
}
2630
],
2731
"database_specific": {
28-
"cwe_ids": [],
32+
"cwe_ids": [
33+
"CWE-212"
34+
],
2935
"severity": "LOW",
3036
"github_reviewed": false,
3137
"github_reviewed_at": null,

advisories/unreviewed/2026/02/GHSA-qmgg-3m8p-p8cc/GHSA-qmgg-3m8p-p8cc.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,17 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-qmgg-3m8p-p8cc",
4-
"modified": "2026-02-03T00:30:19Z",
4+
"modified": "2026-03-25T15:31:24Z",
55
"published": "2026-02-03T00:30:19Z",
66
"aliases": [
77
"CVE-2025-61641"
88
],
99
"details": "Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQueryAllPages.Php.\n\nThis issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.",
1010
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
14+
},
1115
{
1216
"type": "CVSS_V4",
1317
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"

advisories/unreviewed/2026/02/GHSA-v564-5h76-v6ch/GHSA-v564-5h76-v6ch.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,17 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-v564-5h76-v6ch",
4-
"modified": "2026-02-03T03:30:26Z",
4+
"modified": "2026-03-25T15:31:24Z",
55
"published": "2026-02-03T03:30:26Z",
66
"aliases": [
77
"CVE-2025-61646"
88
],
99
"details": "Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php.\n\nThis issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.",
1010
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
14+
},
1115
{
1216
"type": "CVSS_V4",
1317
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2f5p-h4fx-2cqj",
4+
"modified": "2026-03-25T15:31:29Z",
5+
"published": "2026-03-25T15:31:29Z",
6+
"aliases": [
7+
"CVE-2026-3126"
8+
],
9+
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3126"
16+
}
17+
],
18+
"database_specific": {
19+
"cwe_ids": [],
20+
"severity": null,
21+
"github_reviewed": false,
22+
"github_reviewed_at": null,
23+
"nvd_published_at": "2026-03-25T15:16:50Z"
24+
}
25+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3222-m64x-qwpg",
4+
"modified": "2026-03-25T15:31:29Z",
5+
"published": "2026-03-25T15:31:29Z",
6+
"aliases": [
7+
"CVE-2025-27260"
8+
],
9+
"details": "Ericsson\nIndoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special\nElements vulnerability which, if exploited, can lead to unauthorized\nmodification of certain information",
10+
"severity": [
11+
{
12+
"type": "CVSS_V4",
13+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27260"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://www.ericsson.com/en/about-us/security/psirt/CVE-2025-27260"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-indoorconnect-march-2026"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-790"
34+
],
35+
"severity": "HIGH",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-03-25T14:16:30Z"
39+
}
40+
}

0 commit comments

Comments
 (0)