Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-06-03 21:32:05 +00:00
parent 290c6582b6
commit 2326af2cad
50 changed files with 680 additions and 67 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-87g3-rx63-rrch",
"modified": "2022-09-18T00:00:32Z",
"modified": "2025-06-03T21:30:30Z",
"published": "2022-09-17T00:00:36Z",
"aliases": [
"CVE-2021-42949"
@@ -34,6 +34,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287",
"CWE-326"
],
"severity": "CRITICAL",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pfjw-c288-q656",
"modified": "2022-09-23T00:00:42Z",
"modified": "2025-06-03T21:30:32Z",
"published": "2022-09-20T00:00:22Z",
"aliases": [
"CVE-2022-23767"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8xhg-wqv3-qqf5",
"modified": "2023-12-14T15:30:23Z",
"modified": "2025-06-03T21:30:33Z",
"published": "2023-12-14T15:30:23Z",
"aliases": [
"CVE-2023-49739"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/powerpack-elements/wordpress-powerpack-pro-for-elementor-plugin-2-9-23-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/powerpack-elements/vulnerability/wordpress-powerpack-pro-for-elementor-plugin-2-9-23-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24gf-6m5f-h6pg",
"modified": "2024-01-31T18:31:26Z",
"modified": "2025-06-03T21:30:33Z",
"published": "2024-01-31T18:31:26Z",
"aliases": [
"CVE-2024-21888"
],
"details": "A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator. ",
"details": "A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.",
"severity": [
{
"type": "CVSS_V3",
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6p66-xcjh-mgwv",
"modified": "2024-01-16T18:31:11Z",
"modified": "2025-06-03T21:30:33Z",
"published": "2024-01-16T18:31:11Z",
"aliases": [
"CVE-2023-37523"
],
"details": "Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.\n",
"details": "Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.",
"severity": [
{
"type": "CVSS_V3",
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jf62-g97c-j9x3",
"modified": "2024-01-09T18:30:27Z",
"modified": "2025-06-03T21:30:32Z",
"published": "2024-01-03T03:30:33Z",
"aliases": [
"CVE-2023-50342"
],
"details": "HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certain details about another user as a result of improper access control.\n",
"details": "HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certain details about another user as a result of improper access control.",
"severity": [
{
"type": "CVSS_V3",
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-285"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jp7h-g39h-xfp6",
"modified": "2024-01-22T15:30:22Z",
"modified": "2025-06-03T21:30:32Z",
"published": "2024-01-16T06:30:31Z",
"aliases": [
"CVE-2024-21673"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pg84-6g27-3r3m",
"modified": "2024-01-17T00:30:21Z",
"modified": "2025-06-03T21:30:33Z",
"published": "2024-01-17T00:30:21Z",
"aliases": [
"CVE-2024-20971"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xvjx-j3q9-j35p",
"modified": "2024-01-17T00:30:21Z",
"modified": "2025-06-03T21:30:33Z",
"published": "2024-01-17T00:30:21Z",
"aliases": [
"CVE-2024-20969"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cwc-8x85-2774",
"modified": "2024-02-02T21:31:29Z",
"modified": "2025-06-03T21:30:33Z",
"published": "2024-02-02T21:31:29Z",
"aliases": [
"CVE-2024-23553"
],
"details": "A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute. \n",
"details": "A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.",
"severity": [
{
"type": "CVSS_V3",

Some files were not shown because too many files have changed in this diff Show More