Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-02-26 00:33:39 +00:00
parent 92f9c5085b
commit 33726584d5
35 changed files with 502 additions and 27 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wmh3-5pfq-qpp8",
"modified": "2023-03-28T21:30:20Z",
"modified": "2025-02-26T00:32:07Z",
"published": "2023-03-23T00:30:16Z",
"aliases": [
"CVE-2023-27100"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://docs.netgate.com/downloads/pfSense-SA-23_05.sshguard.asc"
},
{
"type": "WEB",
"url": "https://packetstorm.news/files/id/171791"
},
{
"type": "WEB",
"url": "https://redmine.pfsense.org/issues/13574"
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8q86-4x73-99v8",
"modified": "2024-02-26T18:30:29Z",
"modified": "2025-02-26T00:32:11Z",
"published": "2024-02-26T18:30:29Z",
"aliases": [
"CVE-2024-0387"
],
"details": "The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.\n\n",
"details": "The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfq7-h592-v3xj",
"modified": "2024-03-28T09:31:12Z",
"modified": "2025-02-26T00:32:10Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-24681"
],
"details": "Insecure AES key in Yealink Configuration Encrypt Tool below verrsion 1.2. A single, vendorwide, hardcoded AES key in the configuration tool used to encrypt provisioning documents was leaked leading to a compromise of confidentiality of provisioning documents.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-798"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T23:15:09Z"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhhw-3vhx-mm3g",
"modified": "2024-06-25T15:31:09Z",
"modified": "2025-02-26T00:32:11Z",
"published": "2024-06-25T15:31:09Z",
"aliases": [
"CVE-2023-37541"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37541"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119435"
},
{
"type": "WEB",
"url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0114156"
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hggj-xw9j-66ph",
"modified": "2025-01-07T06:32:16Z",
"modified": "2025-02-26T00:32:16Z",
"published": "2025-01-07T06:32:16Z",
"aliases": [
"CVE-2024-9702"
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pq6f-c6w9-6488",
"modified": "2025-02-26T00:32:12Z",
"published": "2025-01-03T03:30:29Z",
"aliases": [
"CVE-2025-0175"
],
"details": "A vulnerability was found in code-projects Online Shop 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument name/details leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0175"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/th4s1s/fc65dafa7237cc66a18ef6005075c31b"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.290104"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.290104"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.473333"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T01:15:08Z"
}
}
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v26g-qqjw-5qgq",
"modified": "2025-01-04T09:35:20Z",
"modified": "2025-02-26T00:32:15Z",
"published": "2025-01-04T09:35:20Z",
"aliases": [
"CVE-2024-11930"
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2gg3-vm5q-jcq2",
"modified": "2025-02-25T18:31:24Z",
"modified": "2025-02-26T00:32:19Z",
"published": "2025-02-25T18:31:24Z",
"aliases": [
"CVE-2025-1067"

Some files were not shown because too many files have changed in this diff Show More