Publish Advisories

GHSA-8qp6-rm76-vj9q
GHSA-25g8-7mhh-fm84
GHSA-2jx2-r7f9-93pw
GHSA-9xv5-7pc9-8rr3
GHSA-8f6m-fvf9-6397
GHSA-jpf5-526x-c5hw
GHSA-3h3m-9w6m-92hw
GHSA-55pf-868x-9jw7
GHSA-5877-58jr-h687
GHSA-778m-4r28-2hp8
GHSA-7wp3-36m3-58j5
GHSA-hh39-985p-g37g
GHSA-j3qf-mq3f-rgcf
GHSA-j6ph-fhmg-qfhg
GHSA-jqw7-hgh5-2ppr
GHSA-jv3c-qh2g-5f2r
GHSA-jwc3-6wrj-fj5w
GHSA-mc52-7658-v986
GHSA-rcj3-h239-hjc8
This commit is contained in:
advisory-database[bot]
2025-06-02 21:32:06 +00:00
parent be637da4ce
commit 42dd304476
19 changed files with 285 additions and 39 deletions
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qp6-rm76-vj9q",
"modified": "2023-12-28T12:30:19Z",
"modified": "2025-06-02T21:30:23Z",
"published": "2023-12-28T12:30:19Z",
"aliases": [
"CVE-2023-50854"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly Squirrly SEO - Advanced Pack.This issue affects Squirrly SEO - Advanced Pack: from n/a through 2.3.8.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly Squirrly SEO - Advanced Pack.This issue affects Squirrly SEO - Advanced Pack: from n/a through 2.3.8.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25g8-7mhh-fm84",
"modified": "2024-02-05T18:31:36Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2024-01-29T15:30:30Z",
"aliases": [
"CVE-2023-7200"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jx2-r7f9-93pw",
"modified": "2024-02-02T18:30:29Z",
"modified": "2025-06-02T21:30:23Z",
"published": "2024-01-29T00:30:17Z",
"aliases": [
"CVE-2024-23782"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9xv5-7pc9-8rr3",
"modified": "2024-02-03T03:30:27Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2024-01-29T15:30:29Z",
"aliases": [
"CVE-2023-6279"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8f6m-fvf9-6397",
"modified": "2025-04-16T21:30:57Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-04-16T21:30:56Z",
"aliases": [
"CVE-2025-31200"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31200"
},
{
"type": "WEB",
"url": "https://blog.noahhw.dev/posts/cve-2025-31200"
},
{
"type": "WEB",
"url": "https://news.ycombinator.com/item?id=44161894"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/122282"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jpf5-526x-c5hw",
"modified": "2025-06-02T12:30:33Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-05-30T15:30:30Z",
"aliases": [
"CVE-2025-40909"
@@ -58,6 +58,14 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/06/02/2"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/06/02/5"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/06/02/6"
}
],
"database_specific": {
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3h3m-9w6m-92hw",
"modified": "2025-06-02T18:30:51Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-06-02T18:30:51Z",
"aliases": [
"CVE-2024-40113"
],
"details": "Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-1392"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T16:15:27Z"
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-55pf-868x-9jw7",
"modified": "2025-06-02T21:30:25Z",
"published": "2025-06-02T21:30:25Z",
"aliases": [
"CVE-2025-23099"
],
"details": "An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23099"
},
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates"
},
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23099"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T19:15:26Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5877-58jr-h687",
"modified": "2025-06-02T21:30:25Z",
"published": "2025-06-02T21:30:25Z",
"aliases": [
"CVE-2025-49069"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Cross Site Request Forgery.This issue affects Contact Forms by Cimatti: from n/a through 1.9.8.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49069"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/contact-forms/vulnerability/wordpress-contact-forms-by-cimatti-plugin-1-9-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T19:15:28Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-778m-4r28-2hp8",
"modified": "2025-06-02T15:31:25Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-06-02T15:31:25Z",
"aliases": [
"CVE-2025-44172"
],
"details": "Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-121"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T15:15:34Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7wp3-36m3-58j5",
"modified": "2025-06-02T18:30:52Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-06-02T18:30:52Z",
"aliases": [
"CVE-2025-44115"
],
"details": "A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads to cross-site scripting.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T16:15:29Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hh39-985p-g37g",
"modified": "2025-06-02T18:30:51Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-06-02T18:30:51Z",
"aliases": [
"CVE-2024-40114"
],
"details": "A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie to inject malicious JavaScript code.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T16:15:27Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j3qf-mq3f-rgcf",
"modified": "2025-06-02T18:30:51Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-06-02T18:30:51Z",
"aliases": [
"CVE-2024-40112"
],
"details": "A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the \"language\" cookie to include arbitrary files from the server. This vulnerability can be exploited to disclose sensitive information.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-98"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T16:15:26Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6ph-fhmg-qfhg",
"modified": "2025-06-02T21:30:25Z",
"published": "2025-06-02T21:30:25Z",
"aliases": [
"CVE-2025-47585"
],
"details": "Missing Authorization vulnerability in Mage people team Booking and Rental Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through 2.3.8.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47585"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/booking-and-rental-manager-for-woocommerce/vulnerability/wordpress-booking-and-rental-manager-2-3-8-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T20:15:22Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqw7-hgh5-2ppr",
"modified": "2025-06-02T18:30:52Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-06-02T18:30:52Z",
"aliases": [
"CVE-2025-23104"
],
"details": "An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-416"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T18:15:23Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jv3c-qh2g-5f2r",
"modified": "2025-06-02T21:30:25Z",
"published": "2025-06-02T21:30:25Z",
"aliases": [
"CVE-2025-1051"
],
"details": "Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the processing of ALAC data. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the anacapa user. Was ZDI-CAN-25865.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1051"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-25-311"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T19:15:25Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jwc3-6wrj-fj5w",
"modified": "2025-06-02T18:30:53Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-06-02T18:30:52Z",
"aliases": [
"CVE-2025-27956"
],
"details": "Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-22"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T18:15:24Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mc52-7658-v986",
"modified": "2025-06-02T18:30:53Z",
"modified": "2025-06-02T21:30:24Z",
"published": "2025-06-02T18:30:53Z",
"aliases": [
"CVE-2025-45387"
],
"details": "osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T18:15:24Z"
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rcj3-h239-hjc8",
"modified": "2025-06-02T21:30:25Z",
"published": "2025-06-02T21:30:25Z",
"aliases": [
"CVE-2025-23105"
],
"details": "An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23105"
},
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates"
},
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-23105"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-02T19:15:26Z"
}
}