Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-04-01 15:33:38 +00:00
parent cc9317d75e
commit 6516898ff5
242 changed files with 6731 additions and 234 deletions
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-668"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400",
"CWE-416"
],
"severity": "HIGH",
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-912"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-617"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-668"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-246w-8f59-4f74",
"modified": "2024-02-29T03:33:15Z",
"modified": "2025-04-01T15:31:19Z",
"published": "2024-02-29T03:33:14Z",
"aliases": [
"CVE-2023-6923"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-43p8-gcp3-q7w4",
"modified": "2024-02-29T03:33:18Z",
"modified": "2025-04-01T15:31:20Z",
"published": "2024-02-29T03:33:18Z",
"aliases": [
"CVE-2024-25931"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.0.8.\n\n",
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.0.8.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h7g2-m8qw-9mfj",
"modified": "2024-02-28T18:30:32Z",
"modified": "2025-04-01T15:31:18Z",
"published": "2024-02-28T18:30:32Z",
"aliases": [
"CVE-2023-52223"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite WooCommerce integration.This issue affects MailerLite WooCommerce integration: from n/a through 2.0.8.\n\n",
"details": "Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite WooCommerce integration.This issue affects MailerLite WooCommerce integration: from n/a through 2.0.8.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j4j6-xqv7-cqrg",
"modified": "2024-02-29T03:33:18Z",
"modified": "2025-04-01T15:31:20Z",
"published": "2024-02-29T03:33:18Z",
"aliases": [
"CVE-2024-25932"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix.This issue affects Change Table Prefix: from n/a through 2.0.\n\n",
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix.This issue affects Change Table Prefix: from n/a through 2.0.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8g6-6p5x-cv9v",
"modified": "2024-02-29T06:30:33Z",
"modified": "2025-04-01T15:31:22Z",
"published": "2024-02-29T06:30:33Z",
"aliases": [
"CVE-2024-1437"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in José Fernandez Adsmonetizer allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.1.2.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in José Fernandez Adsmonetizer allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.1.2.",
"severity": [
{
"type": "CVSS_V3",
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -45,7 +45,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-416"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29w3-4r4c-4fmm",
"modified": "2025-03-31T15:30:48Z",
"modified": "2025-04-01T15:31:29Z",
"published": "2025-03-31T15:30:48Z",
"aliases": [
"CVE-2025-22940"
],
"details": "Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-284"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-31T15:15:43Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-429p-hfv2-984f",
"modified": "2025-03-31T15:30:48Z",
"modified": "2025-04-01T15:31:29Z",
"published": "2025-03-31T15:30:48Z",
"aliases": [
"CVE-2025-22938"
],
"details": "Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-1393"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-31T15:15:43Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4r7f-8mqg-24xx",
"modified": "2025-03-29T00:31:35Z",
"modified": "2025-04-01T15:31:29Z",
"published": "2025-03-29T00:31:35Z",
"aliases": [
"CVE-2025-28097"
],
"details": "OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T22:15:18Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-57fm-4q7w-88cr",
"modified": "2025-03-28T15:31:56Z",
"modified": "2025-04-01T15:31:29Z",
"published": "2025-03-28T15:31:56Z",
"aliases": [
"CVE-2024-48615"
],
"details": "Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-476"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T15:15:45Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59v2-78g4-8w49",
"modified": "2025-03-26T18:30:51Z",
"modified": "2025-04-01T15:31:29Z",
"published": "2025-03-26T18:30:51Z",
"aliases": [
"CVE-2025-2600"
],
"details": "Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated password to use the ELEVATED_PASSWORD variable even though not allowed by the \"Allow password in variable policy\". \n\n\n\n\n\nThis issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-285"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-26T18:15:26Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7qr-fxvv-x4fh",
"modified": "2025-03-27T18:31:27Z",
"modified": "2025-04-01T15:31:29Z",
"published": "2025-03-27T18:31:27Z",
"aliases": [
"CVE-2023-52990"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gx79-fmcg-96m2",
"modified": "2025-03-31T15:30:48Z",
"modified": "2025-04-01T15:31:29Z",
"published": "2025-03-31T15:30:48Z",
"aliases": [
"CVE-2025-22939"
],
"details": "A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-31T15:15:43Z"

Some files were not shown because too many files have changed in this diff Show More