Publish Advisories

GHSA-cvwm-qh2r-q68h
GHSA-m6hj-x59q-53qg
GHSA-3w22-q3jv-89jw
GHSA-r89w-9fr4-c7c9
GHSA-4wjh-chq6-qh88
GHSA-7f2m-jpcp-wjgr
GHSA-48xq-vmgv-hxqw
GHSA-f69c-c87p-g4rh
GHSA-r8vg-fpvm-r7hh
GHSA-6wm8-q34j-2mc2
GHSA-fwj7-p878-r668
GHSA-pc6x-4v99-366p
GHSA-2v55-9vh6-3j74
GHSA-6rw4-c297-m856
GHSA-8fx6-mj35-8hj9
GHSA-fmxw-76xq-cmqq
GHSA-jxq2-9wwx-p5rm
GHSA-xwcv-8394-675h
This commit is contained in:
advisory-database[bot]
2025-03-22 15:32:08 +00:00
parent 764e538071
commit 585035d84e
18 changed files with 325 additions and 11 deletions
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvwm-qh2r-q68h",
"modified": "2024-10-17T15:31:06Z",
"modified": "2025-03-22T15:30:34Z",
"published": "2024-02-13T18:38:23Z",
"aliases": [
"CVE-2023-20570"
],
"details": "Insufficient verification of data authenticity in\nthe configuration state machine may allow a local attacker to potentially load\narbitrary bitstreams.\n\n\n\n\n\n",
"details": "Insufficient verification of data authenticity in\nthe configuration state machine may allow a local attacker to potentially load\narbitrary bitstreams.",
"severity": [
{
"type": "CVSS_V3",
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -53,7 +53,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -34,6 +34,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-269"
],
"severity": "HIGH",
@@ -42,6 +42,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400",
"CWE-89"
],
"severity": "HIGH",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7f2m-jpcp-wjgr",
"modified": "2024-10-11T15:30:32Z",
"modified": "2025-03-22T15:30:34Z",
"published": "2024-10-11T15:30:32Z",
"aliases": [
"CVE-2024-45317"
],
"details": "A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-918"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-11T13:15:16Z"
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-770"
"CWE-770",
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-863"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-476"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400",
"CWE-617"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-862"
],
"severity": "HIGH",
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-276"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2v55-9vh6-3j74",
"modified": "2025-03-22T15:30:36Z",
"published": "2025-03-22T15:30:36Z",
"aliases": [
"CVE-2025-2619"
],
"details": "A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component Cookie Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2619"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300621"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300621"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.518968"
},
{
"type": "WEB",
"url": "https://witty-maiasaura-083.notion.site/D-link-DAP-1620-check_dws_cookie-Vulnerability-1b4b2f2a6361805ca74fdf4949385ade"
},
{
"type": "WEB",
"url": "https://www.dlink.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-22T14:15:16Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6rw4-c297-m856",
"modified": "2025-03-22T15:30:36Z",
"published": "2025-03-22T15:30:36Z",
"aliases": [
"CVE-2025-2618"
],
"details": "A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2618"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300620"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300620"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.518963"
},
{
"type": "WEB",
"url": "https://witty-maiasaura-083.notion.site/D-link-DAP-1620-set_ws_action-Vulnerability-1afb2f2a6361804e86dcde1e78ea2a8e"
},
{
"type": "WEB",
"url": "https://www.dlink.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-22T14:15:16Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8fx6-mj35-8hj9",
"modified": "2025-03-22T15:30:36Z",
"published": "2025-03-22T15:30:36Z",
"aliases": [
"CVE-2025-2617"
],
"details": "A vulnerability classified as problematic was found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected by this vulnerability is an unknown functionality of the component Department Page. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2617"
},
{
"type": "WEB",
"url": "https://gitee.com/yangyouwang/crud/issues/IBSPOX"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300619"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300619"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-22T13:15:35Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmxw-76xq-cmqq",
"modified": "2025-03-22T15:30:36Z",
"published": "2025-03-22T15:30:36Z",
"aliases": [
"CVE-2025-26796"
],
"details": "** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie.\n\nThis issue affects Apache Oozie: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26796"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/fzrmsslnrpl0vpp0jr73fosmfjv4omdq"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/03/21/1"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-22T13:15:35Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jxq2-9wwx-p5rm",
"modified": "2025-03-22T15:30:36Z",
"published": "2025-03-22T15:30:36Z",
"aliases": [
"CVE-2025-2620"
],
"details": "A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2620"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300622"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300622"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.518969"
},
{
"type": "WEB",
"url": "https://witty-maiasaura-083.notion.site/D-link-DAP-1620-mod_graph_auth_uri_handler-Vulnerability-1afb2f2a6361809ea7f2dc4df3b85f1f"
},
{
"type": "WEB",
"url": "https://www.dlink.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-22T15:15:38Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xwcv-8394-675h",
"modified": "2025-03-22T15:30:36Z",
"published": "2025-03-22T15:30:36Z",
"aliases": [
"CVE-2025-2186"
],
"details": "The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the automationId parameter in all versions up to, and including, 3.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2186"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/wp-marketing-automations/trunk/includes/api/wc/class-bwfan-api-get-automation-dynamic-coupon.php#L50"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3257474"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/88f8fa25-e3d5-4dfd-aae5-68b5880ffd53?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-22T13:15:35Z"
}
}