Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-02-06 15:34:21 +00:00
parent ccea795987
commit 846d62cfc2
39 changed files with 707 additions and 72 deletions
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cwxx-ph2v-87p8",
"modified": "2022-05-24T17:30:26Z",
"modified": "2025-02-06T15:32:50Z",
"published": "2022-05-24T17:30:26Z",
"aliases": [
"CVE-2020-26919"
],
"details": "NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mmm5-f82c-58j8",
"modified": "2025-01-24T18:31:04Z",
"modified": "2025-02-06T15:32:51Z",
"published": "2022-05-24T19:01:29Z",
"aliases": [
"CVE-2021-32030"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AC2900/HelpDesk_BIOS"
},
{
"type": "WEB",
"url": "https://www.asus.com/us/supportonly/lyra%20mini/helpdesk_bios"
},
{
"type": "WEB",
"url": "https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x5v2-fv6f-w5rh",
"modified": "2022-07-13T00:00:50Z",
"modified": "2025-02-06T15:32:50Z",
"published": "2022-05-24T17:40:34Z",
"aliases": [
"CVE-2020-29557"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-276"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7f69-3jw6-qjqw",
"modified": "2024-12-14T09:30:30Z",
"modified": "2025-02-06T15:32:51Z",
"published": "2024-12-14T09:30:30Z",
"aliases": [
"CVE-2024-11715"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35p2-5vrh-m3p6",
"modified": "2025-01-30T15:31:39Z",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-01-30T15:31:39Z",
"aliases": [
"CVE-2024-55417"
],
"details": "DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-30T15:15:17Z"
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276"
"CWE-276",
"CWE-862"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5wjw-qjhm-v43h",
"modified": "2025-01-30T15:31:39Z",
"modified": "2025-02-06T15:32:51Z",
"published": "2025-01-30T15:31:39Z",
"aliases": [
"CVE-2024-53615"
],
"details": "A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-30T15:15:17Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m777-hj92-cw6q",
"modified": "2025-01-30T18:32:07Z",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-01-30T18:32:07Z",
"aliases": [
"CVE-2025-22220"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-269"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-237v-gpwr-jc57",
"modified": "2025-02-05T03:32:13Z",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-02-05T00:31:13Z",
"aliases": [
"CVE-2024-13722"
],
"details": "The \"NagVis\" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -39,7 +44,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-04T22:15:40Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cmr-4r4h-w563",
"modified": "2025-02-06T06:31:26Z",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-02-06T06:31:26Z",
"aliases": [
"CVE-2025-1066"
],
"details": "OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-06T00:15:27Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rjf-p248-343v",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-02-06T15:32:52Z",
"aliases": [
"CVE-2024-57958"
],
"details": "Out-of-bounds array read vulnerability in the FFRT module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57958"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2025/2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-06T13:15:40Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53rp-33p8-4hm8",
"modified": "2025-02-06T06:31:26Z",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-02-06T06:31:26Z",
"aliases": [
"CVE-2024-57074"
],
"details": "A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-1321"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-05T22:15:31Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7qgg-vw88-cc99",
"modified": "2025-02-06T06:31:26Z",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-02-06T06:31:26Z",
"aliases": [
"CVE-2024-57077"
],
"details": "The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-1321"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-05T22:15:31Z"
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7vpm-4pp6-mgv3",
"modified": "2025-02-06T15:32:53Z",
"published": "2025-02-06T15:32:53Z",
"aliases": [
"CVE-2024-57962"
],
"details": "Vulnerability of incomplete verification information in the VPN service module\nImpact: Successful exploitation of this vulnerability may affect availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57962"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2025/2"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-06T13:15:40Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xvx-6q95-x86w",
"modified": "2025-02-05T00:31:13Z",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-02-05T00:31:13Z",
"aliases": [
"CVE-2024-48445"
],
"details": "An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-287"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-04T23:15:08Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9j5q-479x-43g2",
"modified": "2025-02-06T06:31:26Z",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-02-06T06:31:26Z",
"aliases": [
"CVE-2024-57085"
],
"details": "A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-1321"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-05T22:15:32Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c42g-rmxf-64ch",
"modified": "2025-02-05T12:33:07Z",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-02-05T12:33:07Z",
"aliases": [
"CVE-2025-0167"
],
"details": "When asked to use a `.netrc` file for credentials **and** to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has a `default` entry that\nomits both login and password. A rare circumstance.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-05T10:15:22Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cr8h-hqjg-7fqq",
"modified": "2025-02-06T15:32:52Z",
"published": "2025-02-06T15:32:52Z",
"aliases": [
"CVE-2024-57961"
],
"details": "Out-of-bounds write vulnerability in the emcom module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57961"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2025/2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-06T13:15:40Z"
}
}

Some files were not shown because too many files have changed in this diff Show More