Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-02-11 15:34:11 +00:00
parent fcd2ad181d
commit 584213d3ee
30 changed files with 374 additions and 47 deletions
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9pf-hjmx-3mpq",
"modified": "2022-01-05T00:01:49Z",
"modified": "2025-02-11T15:32:20Z",
"published": "2021-12-24T00:00:41Z",
"aliases": [
"CVE-2021-44600"
],
"details": "The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve all authentication and information about the users of this system.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26mv-q4q7-6xv2",
"modified": "2024-05-17T21:31:47Z",
"modified": "2025-02-11T15:32:20Z",
"published": "2024-05-17T21:31:47Z",
"aliases": [
"CVE-2024-5069"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-56xp-9hrv-5vvj",
"modified": "2024-05-20T09:30:50Z",
"modified": "2025-02-11T15:32:21Z",
"published": "2024-05-20T09:30:50Z",
"aliases": [
"CVE-2024-5134"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7vww-mjq5-vh3j",
"modified": "2024-05-14T18:30:57Z",
"modified": "2025-02-11T15:32:20Z",
"published": "2024-05-14T18:30:57Z",
"aliases": [
"CVE-2024-4809"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w6j9-gj52-h6wf",
"modified": "2024-05-14T18:30:57Z",
"modified": "2025-02-11T15:32:20Z",
"published": "2024-05-14T18:30:57Z",
"aliases": [
"CVE-2024-4820"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xmcr-r54g-jx72",
"modified": "2024-05-14T18:30:57Z",
"modified": "2025-02-11T15:32:20Z",
"published": "2024-05-14T18:30:57Z",
"aliases": [
"CVE-2024-4798"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gcp5-jr9j-3744",
"modified": "2024-06-02T15:30:37Z",
"modified": "2025-02-11T15:32:21Z",
"published": "2024-06-02T15:30:37Z",
"aliases": [
"CVE-2024-5588"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vh5q-rxqq-3f32",
"modified": "2025-02-11T15:32:21Z",
"published": "2025-01-08T21:32:25Z",
"aliases": [
"CVE-2025-0291"
],
"details": "Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0291"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/383356864"
}
],
"database_specific": {
"cwe_ids": [
"CWE-843"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-08T19:15:38Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3px5-66w8-x4q8",
"modified": "2025-02-10T21:31:37Z",
"modified": "2025-02-11T15:32:22Z",
"published": "2025-02-10T21:31:37Z",
"aliases": [
"CVE-2024-27859"
],
"details": "The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, macOS Sonoma 14.4. Processing web content may lead to arbitrary code execution.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-10T19:15:37Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-83c6-cpc7-fc84",
"modified": "2025-02-11T15:32:24Z",
"published": "2025-02-11T15:32:24Z",
"aliases": [
"CVE-2025-26492"
],
"details": "In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26492"
},
{
"type": "WEB",
"url": "https://www.jetbrains.com/privacy-security/issues-fixed"
}
],
"database_specific": {
"cwe_ids": [
"CWE-522"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-11T14:15:31Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w92-pvrp-jcwv",
"modified": "2025-02-11T12:30:55Z",
"modified": "2025-02-11T15:32:24Z",
"published": "2025-02-11T12:30:55Z",
"aliases": [
"CVE-2025-0588"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://advisories.octopus.com/post/2024/sa2025-05"
},
{
"type": "WEB",
"url": "https://advisories.octopus.com/post/2025/sa2025-05"
}
],
"database_specific": {
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9cmp-ppm3-hp8w",
"modified": "2025-02-11T12:30:54Z",
"modified": "2025-02-11T15:32:23Z",
"published": "2025-02-11T12:30:53Z",
"aliases": [
"CVE-2025-26409"
],
"details": "A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -25,9 +30,10 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1191"
"CWE-1191",
"CWE-1299"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-11T10:15:09Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9fmx-g36w-qhc9",
"modified": "2025-02-11T06:30:27Z",
"modified": "2025-02-11T15:32:22Z",
"published": "2025-02-11T06:30:27Z",
"aliases": [
"CVE-2024-13543"
],
"details": "The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-11T06:15:19Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-chvr-56gh-gq34",
"modified": "2025-02-11T12:30:55Z",
"modified": "2025-02-11T15:32:24Z",
"published": "2025-02-11T12:30:55Z",
"aliases": [
"CVE-2025-26490"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-246355.html"
},
{
"type": "WEB",
"url": "https://help.salesforce.com/s/articleView?id=000390611&type=1"
}
],
"database_specific": {
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9f9-r2j7-9685",
"modified": "2025-02-11T12:30:54Z",
"modified": "2025-02-11T15:32:24Z",
"published": "2025-02-11T12:30:54Z",
"aliases": [
"CVE-2025-26411"
],
"details": "An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device. This enables an attacker to gain remote root access to the device. An attacker needs a valid user account on the Wattsense web interface to be able to conduct this attack. This issue is fixed in recent firmware versions BSP >= 6.1.0.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-11T10:15:09Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hrwq-g9x9-jmq2",
"modified": "2025-02-11T12:30:54Z",
"modified": "2025-02-11T15:32:23Z",
"published": "2025-02-11T12:30:53Z",
"aliases": [
"CVE-2025-26408"
],
"details": "The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-1191"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-11T10:15:09Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hvw5-4g4q-2h8p",
"modified": "2025-02-11T06:30:24Z",
"modified": "2025-02-11T15:32:22Z",
"published": "2025-02-10T21:31:39Z",
"aliases": [
"CVE-2025-24200"
],
"details": "An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-863"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-10T19:15:40Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj4x-g447-hm4m",
"modified": "2025-02-11T12:30:54Z",
"modified": "2025-02-11T15:32:23Z",
"published": "2025-02-11T12:30:54Z",
"aliases": [
"CVE-2025-26410"
],
"details": "The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-798"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-11T10:15:09Z"

Some files were not shown because too many files have changed in this diff Show More