Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-03-25 21:33:22 +00:00
parent 884734f33c
commit 19243617e3
46 changed files with 787 additions and 50 deletions
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-190",
"CWE-20",
"CWE-369"
],
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2x6-rvvf-2x2v",
"modified": "2023-02-14T21:30:30Z",
"modified": "2025-03-25T21:31:26Z",
"published": "2023-02-06T21:30:29Z",
"aliases": [
"CVE-2023-25016"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v8ff-vmc3-wr4m",
"modified": "2023-02-13T15:30:27Z",
"modified": "2025-03-25T21:31:24Z",
"published": "2023-02-04T21:30:22Z",
"aliases": [
"CVE-2023-25193"
@@ -31,6 +31,14 @@
"type": "WEB",
"url": "https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hh"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZ5M2GSAIHFPLHYJXUPQ2QDJCLWXUGO3"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9q54-pg8p-25cg",
"modified": "2024-03-28T06:30:45Z",
"modified": "2025-03-25T21:31:29Z",
"published": "2024-03-28T06:30:45Z",
"aliases": [
"CVE-2024-0677"
],
"details": "The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T05:15:49Z"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wgjq-hm36-r7r8",
"modified": "2024-04-30T18:30:33Z",
"modified": "2025-03-25T21:31:29Z",
"published": "2024-04-30T18:30:33Z",
"aliases": [
"CVE-2019-19752"
],
"details": "nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated plans to fix this in the next image build.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-321"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-30T18:15:19Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xcfg-gmff-9p95",
"modified": "2024-04-30T00:30:34Z",
"modified": "2025-03-25T21:31:29Z",
"published": "2024-04-30T00:30:34Z",
"aliases": [
"CVE-2024-33401"
],
"details": "Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum parameter.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T22:15:06Z"
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-262h-qq26-j72g",
"modified": "2024-05-14T18:30:47Z",
"modified": "2025-03-25T21:31:30Z",
"published": "2024-05-14T18:30:47Z",
"aliases": [
"CVE-2024-32736"
],
"details": "A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the \"query_utask_verbose\" function within MCUDBHelper.\n",
"details": "A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the \"query_utask_verbose\" function within MCUDBHelper.",
"severity": [
{
"type": "CVSS_V3",
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5wq8-45w5-cxgr",
"modified": "2024-05-15T06:30:44Z",
"modified": "2025-03-25T21:31:30Z",
"published": "2024-05-15T06:30:44Z",
"aliases": [
"CVE-2024-3631"
],
"details": "The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-15T06:15:13Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8q5c-h63v-v869",
"modified": "2024-05-08T06:30:48Z",
"modified": "2025-03-25T21:31:30Z",
"published": "2024-05-08T06:30:48Z",
"aliases": [
"CVE-2024-1076"
],
"details": "The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T06:15:06Z"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xmjw-8f7c-p37x",
"modified": "2024-05-02T06:30:32Z",
"modified": "2025-03-25T21:31:29Z",
"published": "2024-05-02T06:30:32Z",
"aliases": [
"CVE-2024-3478"
],
"details": "The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:51Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mgqc-jwxc-fx8x",
"modified": "2024-06-14T06:34:49Z",
"modified": "2025-03-25T21:31:31Z",
"published": "2024-06-14T06:34:49Z",
"aliases": [
"CVE-2024-4480"
],
"details": "The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-14T06:15:13Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x6g9-g4wf-qrf7",
"modified": "2024-08-21T15:30:49Z",
"modified": "2025-03-25T21:31:31Z",
"published": "2024-07-01T21:31:14Z",
"aliases": [
"CVE-2024-38474"
@@ -26,6 +26,10 @@
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240712-0001"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/01/7"
}
],
"database_specific": {
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-295"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xfx-2vr5-pf8q",
"modified": "2025-03-15T12:32:56Z",
"modified": "2025-03-25T21:31:32Z",
"published": "2025-03-15T12:32:56Z",
"aliases": [
"CVE-2025-2025"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4q6p-vw5p-724c",
"modified": "2025-03-25T21:31:34Z",
"published": "2025-03-25T21:31:34Z",
"aliases": [
"CVE-2025-27833"
],
"details": "An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27833"
},
{
"type": "WEB",
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=708259"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T21:15:42Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52fg-w63x-36xq",
"modified": "2025-03-25T21:31:34Z",
"published": "2025-03-25T21:31:34Z",
"aliases": [
"CVE-2025-27832"
],
"details": "An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27832"
},
{
"type": "WEB",
"url": "https://bugs.ghostscript.com/show_bug.cgi?id=708133"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T21:15:42Z"
}
}
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More