Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-02-24 15:32:36 +00:00
parent 442c00efc9
commit 1bc114ba05
75 changed files with 2166 additions and 28 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9442-gm4v-r222",
"modified": "2024-11-29T12:31:48Z",
"modified": "2025-02-24T15:30:22Z",
"published": "2024-06-20T15:31:19Z",
"aliases": [
"CVE-2024-6162"
@@ -51,14 +51,11 @@
"introduced": "0"
},
{
"fixed": "2.3.14.Final"
"fixed": "2.2.33.Final"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "< 2.2.33.Final"
}
]
}
],
"references": [
@@ -102,6 +99,14 @@
"type": "PACKAGE",
"url": "https://github.com/undertow-io/undertow"
},
{
"type": "WEB",
"url": "https://github.com/undertow-io/undertow/releases/tag/2.2.33.Final"
},
{
"type": "WEB",
"url": "https://github.com/undertow-io/undertow/releases/tag/2.3.14.Final"
},
{
"type": "WEB",
"url": "https://issues.redhat.com/browse/JBEAP-26268"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44qf-gpjx-pm9g",
"modified": "2022-05-24T19:19:32Z",
"modified": "2025-02-24T15:30:42Z",
"published": "2022-05-24T19:19:32Z",
"aliases": [
"CVE-2021-43141"
],
"details": "Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73jm-6x85-hwg5",
"modified": "2022-05-13T01:14:58Z",
"modified": "2025-02-24T15:30:41Z",
"published": "2022-05-13T01:14:58Z",
"aliases": [
"CVE-2019-1652"
@@ -54,6 +54,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20",
"CWE-78"
],
"severity": "HIGH",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74vv-6p4c-8fhj",
"modified": "2022-05-24T17:15:13Z",
"modified": "2025-02-24T15:30:41Z",
"published": "2022-05-24T17:15:13Z",
"aliases": [
"CVE-2020-3161"
],
"details": "A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3c8-67q5-2xw8",
"modified": "2022-05-24T19:19:32Z",
"modified": "2025-02-24T15:30:41Z",
"published": "2022-05-24T19:19:32Z",
"aliases": [
"CVE-2021-43140"
],
"details": "SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hgvv-9m7h-78q7",
"modified": "2023-04-03T18:32:08Z",
"modified": "2025-02-24T15:30:45Z",
"published": "2023-03-28T00:34:28Z",
"aliases": [
"CVE-2022-48353"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-269"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jrrq-62hw-r9fw",
"modified": "2023-04-03T18:32:07Z",
"modified": "2025-02-24T15:30:44Z",
"published": "2023-03-28T00:34:28Z",
"aliases": [
"CVE-2022-48352"
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frh3-73v3-rg46",
"modified": "2024-03-29T15:30:31Z",
"modified": "2025-02-24T15:30:46Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30426"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements allows Stored XSS.This issue affects Hash Elements: from n/a through 1.3.3.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements allows Stored XSS.This issue affects Hash Elements: from n/a through 1.3.3.",
"severity": [
{
"type": "CVSS_V3",
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25gx-qr96-f826",
"modified": "2025-02-24T15:30:53Z",
"published": "2025-02-24T15:30:53Z",
"aliases": [
"CVE-2025-27349"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts allows Stored XSS. This issue affects Get Posts: from n/a through 0.6.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27349"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/nurelm-get-posts/vulnerability/wordpress-get-posts-plugin-0-6-stored-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:20Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26mm-6qr4-6xj3",
"modified": "2025-02-24T15:30:49Z",
"published": "2025-02-24T15:30:49Z",
"aliases": [
"CVE-2024-12916"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Life4All allows SQL Injection.This issue affects Life4All: before 10.01.2025.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12916"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-25-0042"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:12Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2824-52jc-w55m",
"modified": "2025-02-24T15:30:52Z",
"published": "2025-02-24T15:30:52Z",
"aliases": [
"CVE-2025-27325"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruce Video.js HLS Player allows DOM-Based XSS. This issue affects Video.js HLS Player: from n/a through 1.0.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27325"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/videojs-hls-player/vulnerability/wordpress-video-js-hls-player-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:18Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-297w-r8j3-c69q",
"modified": "2025-02-24T15:30:53Z",
"published": "2025-02-24T15:30:52Z",
"aliases": [
"CVE-2025-27329"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup allows DOM-Based XSS. This issue affects EZ InLinkz linkup: from n/a through 0.18.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27329"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/inlinkz-scripter/vulnerability/wordpress-ez-inlinkz-linkup-plugin-0-18-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:18Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3775-gcxp-8pxm",
"modified": "2025-02-24T15:30:53Z",
"published": "2025-02-24T15:30:53Z",
"aliases": [
"CVE-2025-27335"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Free plug in by SEO Roma Auto Tag Links allows Cross Site Request Forgery. This issue affects Auto Tag Links: from n/a through 1.0.13.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27335"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/auto-tag-links/vulnerability/wordpress-auto-tag-links-plugin-1-0-13-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:19Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3m4p-3m6j-4rq2",
"modified": "2025-02-24T15:30:51Z",
"published": "2025-02-24T15:30:51Z",
"aliases": [
"CVE-2025-27277"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in tiefpunkt Add Linked Images To Gallery allows Cross Site Request Forgery. This issue affects Add Linked Images To Gallery: from n/a through 1.4.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27277"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/add-linked-images-to-gallery-v01/vulnerability/wordpress-add-linked-images-to-gallery-plugin-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:14Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qqr-67hg-8c4v",
"modified": "2025-02-24T15:30:52Z",
"published": "2025-02-24T15:30:52Z",
"aliases": [
"CVE-2025-27323"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jon Bishop WP About Author allows DOM-Based XSS. This issue affects WP About Author: from n/a through 1.5.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27323"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/wp-about-author/vulnerability/wordpress-wp-about-author-plugin-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:17Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x3j-pmx9-j3r7",
"modified": "2025-02-24T15:30:50Z",
"published": "2025-02-24T15:30:50Z",
"aliases": [
"CVE-2025-23017"
],
"details": "WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23017"
},
{
"type": "WEB",
"url": "https://workos.com/security/advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-305"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:13Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-486p-pvq9-8w7q",
"modified": "2025-02-24T15:30:53Z",
"published": "2025-02-24T15:30:53Z",
"aliases": [
"CVE-2025-27344"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in filipstepanov Phee's LinkPreview allows Cross Site Request Forgery. This issue affects Phee's LinkPreview: from n/a through 1.6.7.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27344"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/linkpreview/vulnerability/wordpress-phee-s-linkpreview-plugin-1-6-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:19Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mw2-mw6m-p7x4",
"modified": "2025-02-24T15:30:53Z",
"published": "2025-02-24T15:30:53Z",
"aliases": [
"CVE-2025-27351"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpertBusinessSearch Local Search SEO Contact Page allows Stored XSS. This issue affects Local Search SEO Contact Page: from n/a through 4.0.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27351"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/local-search-seo-contact-page/vulnerability/wordpress-local-search-seo-contact-page-plugin-4-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:20Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5553-rf4f-g9qc",
"modified": "2025-02-24T15:30:50Z",
"published": "2025-02-24T15:30:50Z",
"aliases": [
"CVE-2024-12917"
],
"details": "Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorrectly Configured Access Control Security Levels, Authentication Abuse.This issue affects Health4All: before 10.01.2025.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12917"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-25-0042"
}
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:12Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-56c7-jcxw-47mf",
"modified": "2025-02-24T15:30:52Z",
"published": "2025-02-24T15:30:52Z",
"aliases": [
"CVE-2025-27318"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in ixiter Simple Google Sitemap allows Cross Site Request Forgery. This issue affects Simple Google Sitemap: from n/a through 1.6.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27318"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/simple-google-sitemap/vulnerability/wordpress-simple-google-sitemap-plugin-1-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T15:15:17Z"
}
}

Some files were not shown because too many files have changed in this diff Show More