Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-06-11 15:31:59 +00:00
parent f897dfba97
commit 888f13e9c7
49 changed files with 721 additions and 91 deletions
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p5c8-x5qh-v2mv",
"modified": "2021-12-24T00:01:14Z",
"modified": "2025-06-11T15:30:23Z",
"published": "2021-12-16T00:01:41Z",
"aliases": [
"CVE-2021-43905"
],
"details": "Microsoft Office app Remote Code Execution Vulnerability",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2986-9f3x-j93c",
"modified": "2023-11-16T18:30:28Z",
"modified": "2025-06-11T15:30:23Z",
"published": "2023-11-09T06:30:28Z",
"aliases": [
"CVE-2023-47488"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9h6-5vxm-9xx3",
"modified": "2023-12-05T21:31:00Z",
"modified": "2025-06-11T15:30:24Z",
"published": "2023-11-16T09:30:24Z",
"aliases": [
"CVE-2023-47674"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p99v-qjfm-8vvq",
"modified": "2023-11-28T21:30:24Z",
"modified": "2025-06-11T15:30:24Z",
"published": "2023-11-11T03:30:16Z",
"aliases": [
"CVE-2023-46849"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ph4x-8w6x-4q6x",
"modified": "2023-11-21T03:30:25Z",
"modified": "2025-06-11T15:30:24Z",
"published": "2023-11-16T00:30:55Z",
"aliases": [
"CVE-2023-48197"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj7c-wrfh-7qqh",
"modified": "2024-04-18T00:30:32Z",
"modified": "2025-06-11T15:30:24Z",
"published": "2024-04-18T00:30:32Z",
"aliases": [
"CVE-2024-3932"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -19,6 +23,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3932"
},
{
"type": "WEB",
"url": "https://totara.community/mod/forum/discuss.php?d=27644"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.261369"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-290"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-601"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22v5-q59j-h85m",
"modified": "2025-06-11T03:31:07Z",
"modified": "2025-06-11T15:30:28Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2025-5959"
],
"details": "Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-843"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T01:15:21Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2972-gp35-c62r",
"modified": "2025-06-10T18:32:31Z",
"modified": "2025-06-11T15:30:27Z",
"published": "2025-06-10T18:32:31Z",
"aliases": [
"CVE-2024-37395"
],
"details": "A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-10T18:15:29Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vc6-9c9h-vvhf",
"modified": "2025-06-11T15:30:29Z",
"published": "2025-06-11T15:30:29Z",
"aliases": [
"CVE-2025-3473"
],
"details": "IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3473"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7236356"
}
],
"database_specific": {
"cwe_ids": [
"CWE-277"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T15:15:29Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wpw-3v5g-3wff",
"modified": "2025-06-11T00:30:48Z",
"modified": "2025-06-11T15:30:28Z",
"published": "2025-06-11T00:30:48Z",
"aliases": [
"CVE-2025-47849"
],
"details": "A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation is not appropriately restricted and allows the attacker to assume control over higher-privileged user-accounts. A malicious Domain Admin attacker can impersonate an Admin user-account and gain access to sensitive APIs and resources that could result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of infrastructure managed by CloudStack.\n\nUsers are recommended to upgrade to Apache CloudStack 4.19.3.0 or 4.20.1.0, which fixes the issue with the following:\n\n\n * Strict validation on Role Type hierarchy: the caller's role must be equal to or higher than the target user's role. \n * API privilege comparison: the caller must possess all privileges of the user they are operating on. \n * Two new domain-level settings (restricted to the default admin): \n- role.types.allowed.for.operations.on.accounts.of.same.role.type: Defines which role types are allowed to act on users of the same role type. Default: \"Admin, DomainAdmin, ResourceAdmin\". \n- allow.operations.on.users.in.same.account: Allows/disallows user operations within the same account. Default: true.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -31,7 +36,7 @@
"cwe_ids": [
"CWE-269"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-10T23:15:58Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3fxc-2crv-fg9x",
"modified": "2025-06-10T21:31:22Z",
"modified": "2025-06-11T15:30:27Z",
"published": "2025-06-10T18:32:32Z",
"aliases": [
"CVE-2025-2884"
],
"details": "TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 of TCG standard TPM2.0",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -22,6 +27,10 @@
"type": "WEB",
"url": "https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-v1.83-Errata_v1_pub.pdf"
},
{
"type": "WEB",
"url": "https://trustedcomputinggroup.org/wp-content/uploads/VRT0009-Advisory-FINAL.pdf"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01209.html"
@@ -32,8 +41,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-125"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-10T18:15:30Z"
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-48wx-8736-jgx2",
"modified": "2025-06-11T15:30:29Z",
"published": "2025-06-11T15:30:29Z",
"aliases": [
"CVE-2025-48446"
],
"details": "Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.0.0 before 1.0.3.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48446"
},
{
"type": "WEB",
"url": "https://www.drupal.org/sa-contrib-2025-067"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T15:15:42Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-57x8-g7cj-crwq",
"modified": "2025-06-10T21:31:23Z",
"modified": "2025-06-11T15:30:27Z",
"published": "2025-06-10T21:31:23Z",
"aliases": [
"CVE-2024-41504"
],
"details": "Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the \"Oportunidades\" (opportunities) section of the application when creating or editing an \"Atividade\" (activity), the form field \"Descrico\" allows injection of JavaScript.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-10T20:15:21Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6236-fhhc-64mr",
"modified": "2025-06-10T12:30:18Z",
"modified": "2025-06-11T15:30:26Z",
"published": "2025-06-10T12:30:18Z",
"aliases": [
"CVE-2025-43697"
],
"details": "Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data.\nThis impacts OmniStudio: before Spring 2025",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-281"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-10T12:15:24Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-64mp-f6ff-c8jm",
"modified": "2025-06-11T12:30:36Z",
"modified": "2025-06-11T15:30:28Z",
"published": "2025-06-11T12:30:36Z",
"aliases": [
"CVE-2025-49710"
],
"details": "An integer overflow was present in `OrderedHashTable` used by the JavaScript engine This vulnerability affects Firefox < 139.0.4.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-190"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T12:15:27Z"

Some files were not shown because too many files have changed in this diff Show More