Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-05-30 18:32:47 +00:00
parent bbe8b5c9d1
commit 58c5bac7f6
115 changed files with 1140 additions and 145 deletions
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-87r3-r32q-8qpf",
"modified": "2021-12-23T00:01:52Z",
"modified": "2025-05-30T18:30:41Z",
"published": "2021-12-18T00:01:02Z",
"aliases": [
"CVE-2021-44035"
],
"details": "Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44035"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-44035"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2021-44035"
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jx3f-hj4m-h7p9",
"modified": "2021-12-11T00:01:10Z",
"modified": "2025-05-30T18:30:41Z",
"published": "2021-12-09T00:00:39Z",
"aliases": [
"CVE-2021-42110"
],
"details": "An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42110"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-42110"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2021-42110"
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x8r9-m3mh-g58r",
"modified": "2021-12-14T00:01:30Z",
"modified": "2025-05-30T18:30:41Z",
"published": "2021-12-09T00:00:33Z",
"aliases": [
"CVE-2021-43978"
],
"details": "Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-43978"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-43978"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2021-43978"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mj5-r67q-gqfq",
"modified": "2022-03-17T00:04:14Z",
"modified": "2025-05-30T18:30:42Z",
"published": "2022-03-03T00:00:49Z",
"aliases": [
"CVE-2022-24447"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24447"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-24447"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/cve-2022-24447"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fq7v-xj92-r9mr",
"modified": "2022-03-17T00:04:32Z",
"modified": "2025-05-30T18:30:42Z",
"published": "2022-03-02T00:00:21Z",
"aliases": [
"CVE-2022-24446"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24446"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-24446"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory"
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2c4q-25x9-p644",
"modified": "2022-05-24T19:06:33Z",
"modified": "2025-05-30T18:30:39Z",
"published": "2022-05-24T19:06:33Z",
"aliases": [
"CVE-2021-31160"
],
"details": "Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31160"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-31160"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/cve-2021-31160"
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34xh-3qm2-46mg",
"modified": "2022-05-24T17:40:33Z",
"modified": "2025-05-30T18:30:38Z",
"published": "2022-05-24T17:40:33Z",
"aliases": [
"CVE-2020-28401"
],
"details": "An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28401"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28401"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28401"
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mmf-jfc6-j4wj",
"modified": "2022-05-24T17:40:33Z",
"modified": "2025-05-30T18:30:39Z",
"published": "2022-05-24T17:40:33Z",
"aliases": [
"CVE-2020-28403"
],
"details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account of the application.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28403"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28403"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28403"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-645f-643g-f2h4",
"modified": "2022-05-13T01:08:16Z",
"modified": "2025-05-30T18:30:34Z",
"published": "2022-05-13T01:08:16Z",
"aliases": [
"CVE-2019-7161"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7161"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2019-7161"
},
{
"type": "WEB",
"url": "https://www.excellium-services.com/cert-xlm-advisory"
},
{
"type": "WEB",
"url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2019-7161"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-76h3-5354-76w2",
"modified": "2022-07-13T00:01:35Z",
"modified": "2025-05-30T18:30:40Z",
"published": "2022-05-24T19:13:15Z",
"aliases": [
"CVE-2021-38616"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38616"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-38616"
},
{
"type": "WEB",
"url": "https://eigentech.com"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7g52-j5fp-g582",
"modified": "2022-07-13T00:01:35Z",
"modified": "2025-05-30T18:30:40Z",
"published": "2022-05-24T19:16:25Z",
"aliases": [
"CVE-2021-38618"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38618"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-38618"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/cve-2021-38618"
@@ -41,7 +41,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-119"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-693"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-82m6-xpgw-xcxg",
"modified": "2022-05-13T01:48:44Z",
"modified": "2025-05-30T18:30:33Z",
"published": "2022-05-13T01:48:44Z",
"aliases": [
"CVE-2018-10207"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10207"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10207"
},
{
"type": "WEB",
"url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10207"
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8474-8f3q-2jhh",
"modified": "2022-05-24T17:40:34Z",
"modified": "2025-05-30T18:30:39Z",
"published": "2022-05-24T17:40:34Z",
"aliases": [
"CVE-2020-28406"
],
"details": "An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28406"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28406"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28406"
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8jc2-pvhh-pcg8",
"modified": "2022-05-24T17:40:34Z",
"modified": "2025-05-30T18:30:39Z",
"published": "2022-05-24T17:40:34Z",
"aliases": [
"CVE-2020-28404"
],
"details": "An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access the Billing page without the appropriate privileges.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28404"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-28404"
},
{
"type": "WEB",
"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28404"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8wpj-w799-92rg",
"modified": "2024-03-21T03:33:34Z",
"modified": "2025-05-30T18:30:34Z",
"published": "2022-05-13T01:19:38Z",
"aliases": [
"CVE-2018-18466"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-18466"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-18466"
},
{
"type": "WEB",
"url": "https://www.excellium-services.com/cert-xlm-advisory"
},
{
"type": "WEB",
"url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-18466"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-96c8-xgpw-cf29",
"modified": "2022-05-13T01:48:44Z",
"modified": "2025-05-30T18:30:33Z",
"published": "2022-05-13T01:48:44Z",
"aliases": [
"CVE-2018-10211"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10211"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10211"
},
{
"type": "WEB",
"url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10211"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9gg4-742m-cc8x",
"modified": "2022-05-13T01:48:44Z",
"modified": "2025-05-30T18:30:34Z",
"published": "2022-05-13T01:48:44Z",
"aliases": [
"CVE-2018-10212"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10212"
},
{
"type": "WEB",
"url": "https://cds.thalesgroup.com/en/tcs-cert/CVE-2018-10212"
},
{
"type": "WEB",
"url": "https://www.excellium-services.com/cert-xlm-advisory/cve-2018-10212"

Some files were not shown because too many files have changed in this diff Show More