Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-05-12 18:32:53 +00:00
parent 502a56936b
commit 873c361aff
43 changed files with 883 additions and 45 deletions
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vr88-2hv2-5jvf",
"modified": "2025-03-14T18:30:39Z",
"modified": "2025-05-12T18:31:20Z",
"published": "2024-05-22T00:30:34Z",
"aliases": [
"CVE-2024-21683"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g3hm-j3wc-jcg9",
"modified": "2025-04-03T00:31:31Z",
"modified": "2025-05-12T18:31:20Z",
"published": "2025-03-28T03:30:24Z",
"aliases": [
"CVE-2025-1860"
],
"details": "Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -31,7 +36,7 @@
"cwe_ids": [
"CWE-338"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T01:15:16Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jh7-c2vv-7qf2",
"modified": "2025-04-30T18:31:55Z",
"modified": "2025-05-12T18:31:20Z",
"published": "2025-04-30T18:31:55Z",
"aliases": [
"CVE-2025-3859"
],
"details": "Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus < 138.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-451"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-30T17:15:50Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6935-g2xg-qvf4",
"modified": "2025-04-22T09:30:35Z",
"modified": "2025-05-12T18:31:20Z",
"published": "2025-04-22T09:30:35Z",
"aliases": [
"CVE-2025-26413"
],
"details": "Improper Input Validation vulnerability in Apache Kvrocks.\n\nThe SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index\nof a string. So it will cause the server to crash due to its index is  out of range.\nThis issue affects Apache Kvrocks: through 2.11.1.\n\nUsers are recommended to upgrade to version 2.12.0, which fixes the issue.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-20"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-22T08:15:28Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfhg-52gw-r6hv",
"modified": "2025-04-21T18:32:09Z",
"modified": "2025-05-12T18:31:20Z",
"published": "2025-04-21T18:32:09Z",
"aliases": [
"CVE-2025-28104"
],
"details": "Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-284"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-21T18:15:22Z"
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27f3-wjfj-399m",
"modified": "2025-05-12T18:31:46Z",
"published": "2025-05-12T18:31:46Z",
"aliases": [
"CVE-2025-45779"
],
"details": "Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45779"
},
{
"type": "WEB",
"url": "https://github.com/sunyou-iot/iot-vul/blob/main/TendaAC10/CVE-2025-45779/README.md"
},
{
"type": "WEB",
"url": "https://www.tendacn.com/us/download/detail-3782.html"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-12T17:15:47Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jfq-w82p-5wx6",
"modified": "2025-05-12T18:31:45Z",
"published": "2025-05-12T18:31:45Z",
"aliases": [
"CVE-2025-46737"
],
"details": "SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway service in the application. This gateway service includes an API which is not properly configured to reject requests from unexpected sources.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46737"
},
{
"type": "WEB",
"url": "https://selinc.com/products/software/latest-software-versions"
}
],
"database_specific": {
"cwe_ids": [
"CWE-346"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-12T16:15:25Z"
}
}
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wvq-34x3-5vhj",
"modified": "2025-05-12T18:31:47Z",
"published": "2025-05-12T18:31:47Z",
"aliases": [
"CVE-2025-46742"
],
"details": "Users who were required to change their password could still access system information before changing their password",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46742"
},
{
"type": "WEB",
"url": "https://selinc.com/products/software/latest-software-versions"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-12T17:15:47Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xwv-25cq-66xr",
"modified": "2025-05-12T18:31:48Z",
"published": "2025-05-12T18:31:48Z",
"aliases": [
"CVE-2023-34732"
],
"details": "An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34732"
},
{
"type": "WEB",
"url": "https://github.com/saykino/CVE-2023-34732"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-12T18:15:43Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g23-7g3r-898j",
"modified": "2025-05-03T18:30:29Z",
"modified": "2025-05-12T18:31:20Z",
"published": "2025-05-03T18:30:29Z",
"aliases": [
"CVE-2024-58134"
],
"details": "Mojolicious versions from 0.999922 through 9.39 for Perl uses a hard coded string, or the application's class name, as a HMAC session secret by default.\n\nThese predictable default secrets can be exploited to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another users session.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -43,7 +48,7 @@
"cwe_ids": [
"CWE-321"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-03T16:15:19Z"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-94"
],
"severity": "MODERATE",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-56gh-5cpc-w3cc",
"modified": "2025-05-02T18:31:38Z",
"modified": "2025-05-12T18:31:21Z",
"published": "2025-05-02T18:31:38Z",
"aliases": [
"CVE-2025-45800"
],
"details": "TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so library, specifically in the processing of the deviceMac parameter.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-02T17:15:52Z"
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cxg-299x-c7pc",
"modified": "2025-05-12T18:31:45Z",
"published": "2025-05-12T18:31:45Z",
"aliases": [
"CVE-2025-44022"
],
"details": "An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44022"
},
{
"type": "WEB",
"url": "https://github.com/givanz/Vvveb/issues/289"
},
{
"type": "WEB",
"url": "https://github.com/givanz/Vvveb/commit/dd74abcae88f658779f61338b9f4c123884eef0d"
},
{
"type": "WEB",
"url": "https://github.com/chimmeee/vulnerability-research/blob/main/CVE-2025-44022"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-12T16:15:25Z"
}
}
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q9m-6mf7-r8rx",
"modified": "2025-05-12T18:31:45Z",
"published": "2025-05-12T18:31:45Z",
"aliases": [
"CVE-2025-44830"
],
"details": "EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44830"
},
{
"type": "WEB",
"url": "https://github.com/3xxx/engineercms/issues/90"
},
{
"type": "WEB",
"url": "https://gist.github.com/LTLTLXEY/e00ec21b730742ef432a7a560cd9b70a"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-12T16:15:25Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7497-r7g9-h259",
"modified": "2025-05-12T18:31:48Z",
"published": "2025-05-12T18:31:48Z",
"aliases": [
"CVE-2025-46745"
],
"details": "An authenticated user without user-management permissions could view other users' account information.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46745"
},
{
"type": "WEB",
"url": "https://selinc.com/products/software/latest-software-versions"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-12T17:15:48Z"
}
}
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More