Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-06-05 18:32:13 +00:00
parent f26ce1a9fc
commit 688dbd9122
26 changed files with 494 additions and 21 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fg7j-3vp4-4qpg",
"modified": "2024-01-31T00:30:17Z",
"modified": "2025-06-05T18:30:33Z",
"published": "2024-01-24T03:31:25Z",
"aliases": [
"CVE-2024-22380"
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jx4-3grj-xm5w",
"modified": "2024-02-14T21:30:32Z",
"modified": "2025-06-05T18:30:34Z",
"published": "2024-02-07T03:30:32Z",
"aliases": [
"CVE-2024-22021"
],
"details": "VulnerabilityCVE-2024-22021 allowsaVeeam Recovery Orchestrator user with a lowprivilegedrole (PlanAuthor)to retrieveplansfromaScope other than the one they are assigned to. \n",
"details": "VulnerabilityCVE-2024-22021 allowsaVeeam Recovery Orchestrator user with a lowprivilegedrole (PlanAuthor)to retrieveplansfromaScope other than the one they are assigned to.",
"severity": [
{
"type": "CVSS_V3",
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-285"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -37,7 +37,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-664"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfhm-jrhg-gr45",
"modified": "2024-02-09T21:30:57Z",
"modified": "2025-06-05T18:30:34Z",
"published": "2024-02-02T18:30:32Z",
"aliases": [
"CVE-2024-22108"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-93h4-qrq6-q2vm",
"modified": "2024-06-12T03:31:15Z",
"modified": "2025-06-05T18:30:34Z",
"published": "2024-06-12T03:31:15Z",
"aliases": [
"CVE-2024-4892"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vh6j-6rmm-669j",
"modified": "2024-08-02T12:31:43Z",
"modified": "2025-06-05T18:30:34Z",
"published": "2024-08-02T12:31:43Z",
"aliases": [
"CVE-2024-6704"
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-75"
"CWE-75",
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fphv-qpcr-r7v5",
"modified": "2024-10-24T09:31:00Z",
"modified": "2025-06-05T18:30:34Z",
"published": "2024-10-24T09:31:00Z",
"aliases": [
"CVE-2024-9531"
@@ -34,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285"
"CWE-285",
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c5f-5rc5-g5mc",
"modified": "2024-12-03T09:31:06Z",
"modified": "2025-06-05T18:30:35Z",
"published": "2024-12-03T09:31:06Z",
"aliases": [
"CVE-2024-11898"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v5rj-qw4c-6pc2",
"modified": "2024-12-04T06:31:01Z",
"modified": "2025-06-05T18:30:35Z",
"published": "2024-12-04T06:31:01Z",
"aliases": [
"CVE-2024-10885"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wg7g-4jwx-j6rf",
"modified": "2025-01-07T09:30:45Z",
"modified": "2025-06-05T18:30:39Z",
"published": "2025-01-07T09:30:45Z",
"aliases": [
"CVE-2024-11282"
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -50,7 +50,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24q6-4w37-557f",
"modified": "2025-06-05T18:30:39Z",
"published": "2025-06-05T18:30:39Z",
"aliases": [
"CVE-2025-5672"
],
"details": "A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5672"
},
{
"type": "WEB",
"url": "https://github.com/byxs0x0/cve2/blob/main/530/2.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.311161"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.311161"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.590094"
},
{
"type": "WEB",
"url": "https://www.totolink.net"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-05T18:15:23Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6h2g-7w8f-c35g",
"modified": "2025-06-05T18:30:39Z",
"published": "2025-06-05T18:30:39Z",
"aliases": [
"CVE-2025-5670"
],
"details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /admin/manage-card.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5670"
},
{
"type": "WEB",
"url": "https://github.com/f1rstb100d/myCVE/issues/52"
},
{
"type": "WEB",
"url": "https://phpgurukul.com"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.311159"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.311159"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.590066"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-05T17:15:30Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84jw-rq34-ghwg",
"modified": "2025-06-05T18:30:39Z",
"published": "2025-06-05T18:30:39Z",
"aliases": [
"CVE-2025-5666"
],
"details": "A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component XMKD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5666"
},
{
"type": "WEB",
"url": "https://fitoxs.com/exploit/exploit-8d9aefc49c178ba5c5d3f5464ff43e8e981c28b95c2cf867d3e20c17f4b9f994.txt"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.311155"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.311155"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.587025"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-05T16:15:27Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8849-vpvc-g9wp",
"modified": "2025-06-05T18:30:39Z",
"published": "2025-06-05T18:30:39Z",
"aliases": [
"CVE-2025-46257"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46257"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/bdthemes-element-pack/vulnerability/wordpress-element-pack-pro-plugin-7-18-12-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-05T18:15:21Z"
}
}

Some files were not shown because too many files have changed in this diff Show More