mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-vgrx-vhjf-p7wv GHSA-393j-fpg3-h6c9 GHSA-fxgj-cfm7-w8hw GHSA-h2w6-c2hx-7jcf GHSA-jc9g-7x7r-c8w7 GHSA-mvh5-v533-3v55 GHSA-q8jx-8wr3-gv52 GHSA-x748-g8vm-gmhw GHSA-657j-69g5-mr77 GHSA-jhvx-96xq-qggm GHSA-659h-jrcq-w3wg GHSA-6pc8-5263-hvgq GHSA-7xmw-644w-wp3m GHSA-mjhr-3845-j2r5
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vgrx-vhjf-p7wv",
|
||||
"modified": "2023-03-21T21:30:19Z",
|
||||
"modified": "2025-02-27T00:30:24Z",
|
||||
"published": "2023-03-15T21:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-28450"
|
||||
@@ -23,6 +23,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://capec.mitre.org/data/definitions/495.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6UQ6LKDTLSSD64TBIZ3XEKBM2SWC63VV"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU2ZT4ITSEOOR2CFBAHK4Z67KXJIEWQA"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6UQ6LKDTLSSD64TBIZ3XEKBM2SWC63VV"
|
||||
@@ -35,6 +43,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://thekelleys.org.uk/dnsmasq/doc.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=blob%3Bf=CHANGELOG"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=eb92fb32b746f2104b0f370b5b295bb8dd4bd5e5"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=blob;f=CHANGELOG"
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-393j-fpg3-h6c9",
|
||||
"modified": "2023-11-10T06:30:18Z",
|
||||
"modified": "2025-02-27T00:30:25Z",
|
||||
"published": "2023-11-06T09:30:15Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45074"
|
||||
],
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.\n\n",
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fxgj-cfm7-w8hw",
|
||||
"modified": "2024-10-10T18:31:07Z",
|
||||
"modified": "2025-02-27T00:30:26Z",
|
||||
"published": "2023-11-09T15:30:30Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4612"
|
||||
],
|
||||
"details": "Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.\n\n\n\n\n\n\n\n\n",
|
||||
"details": "Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h2w6-c2hx-7jcf",
|
||||
"modified": "2023-11-10T06:30:18Z",
|
||||
"modified": "2025-02-27T00:30:25Z",
|
||||
"published": "2023-11-06T09:30:15Z",
|
||||
"aliases": [
|
||||
"CVE-2023-45069"
|
||||
],
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.\n\n",
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jc9g-7x7r-c8w7",
|
||||
"modified": "2023-11-14T18:30:22Z",
|
||||
"modified": "2025-02-27T00:30:25Z",
|
||||
"published": "2023-11-06T12:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46823"
|
||||
],
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.\n\n",
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mvh5-v533-3v55",
|
||||
"modified": "2023-11-10T06:30:18Z",
|
||||
"modified": "2025-02-27T00:30:25Z",
|
||||
"published": "2023-11-06T09:30:15Z",
|
||||
"aliases": [
|
||||
"CVE-2023-35911"
|
||||
],
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.\n\n",
|
||||
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-q8jx-8wr3-gv52",
|
||||
"modified": "2024-11-13T00:30:47Z",
|
||||
"modified": "2025-02-27T00:30:25Z",
|
||||
"published": "2023-11-06T06:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4699"
|
||||
],
|
||||
"details": "Insufficient Verification of Data Authenticity vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules and MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to reset the memory of the products to factory default state and cause denial-of-service (DoS) condition on the products by sending specific packets.\n\n\n\n\n\n\n",
|
||||
"details": "Insufficient Verification of Data Authenticity vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules and MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to reset the memory of the products to factory default state and cause denial-of-service (DoS) condition on the products by sending specific packets.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -27,6 +27,7 @@
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-284",
|
||||
"CWE-683",
|
||||
"CWE-863"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-657j-69g5-mr77",
|
||||
"modified": "2024-05-23T06:30:45Z",
|
||||
"modified": "2025-02-27T00:30:26Z",
|
||||
"published": "2024-05-23T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-5235"
|
||||
@@ -11,6 +11,10 @@
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jhvx-96xq-qggm",
|
||||
"modified": "2024-05-23T06:30:45Z",
|
||||
"modified": "2025-02-27T00:30:26Z",
|
||||
"published": "2024-05-23T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-5236"
|
||||
@@ -11,6 +11,10 @@
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-659h-jrcq-w3wg",
|
||||
"modified": "2025-02-27T00:30:27Z",
|
||||
"published": "2025-02-27T00:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2025-1460"
|
||||
],
|
||||
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1460"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-02-26T23:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6pc8-5263-hvgq",
|
||||
"modified": "2025-02-27T00:30:27Z",
|
||||
"published": "2025-02-27T00:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2024-55581"
|
||||
],
|
||||
"details": "When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55581"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-02-26T22:15:14Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7xmw-644w-wp3m",
|
||||
"modified": "2025-02-27T00:30:27Z",
|
||||
"published": "2025-02-27T00:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2024-53573"
|
||||
],
|
||||
"details": "Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53573"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://drive.google.com/file/d/14Or6QIpOeLEqdFm1mwxdE_NNCOwMmcFc/view"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.getastra.com/blog/vulnerability/improper-access-control-in-school-management-system-unifiedtransform"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-02-26T22:15:14Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mjhr-3845-j2r5",
|
||||
"modified": "2025-02-27T00:30:27Z",
|
||||
"published": "2025-02-27T00:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2024-57040"
|
||||
],
|
||||
"details": "TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained via a brute force attack.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57040"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.iiita.ac.in/iot/hashed_password.pdf"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-02-26T22:15:14Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user