Publish Advisories

GHSA-23qm-j98q-xr7j
GHSA-4j8f-fjpj-x22v
GHSA-59gg-pj3q-72g8
GHSA-62xc-g7hf-p457
GHSA-6m47-c6q4-33vq
GHSA-7c4m-cp34-4f9r
GHSA-h2f3-jpg6-w3c6
GHSA-jcw4-9ccq-g3rh
GHSA-m8ph-fr33-7cmg
GHSA-wxrm-98h4-c857
GHSA-xf9q-jgmw-h653
GHSA-24vc-7q35-w5rv
GHSA-6975-j4h6-fxff
GHSA-j7px-pvwg-2r3m
GHSA-jcc3-vmjf-jfhj
GHSA-mwmr-r556-9837
GHSA-pcwj-m6p3-w8x3
GHSA-rfh5-gx7w-h7v7
GHSA-rrj2-ph5q-jxw2
GHSA-whpg-7794-8rqm
This commit is contained in:
advisory-database[bot]
2025-04-15 06:31:50 +00:00
parent e19e99fa59
commit a05a7fbc6d
20 changed files with 461 additions and 11 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23qm-j98q-xr7j",
"modified": "2022-12-31T00:30:23Z",
"modified": "2025-04-15T06:30:33Z",
"published": "2022-12-23T15:30:24Z",
"aliases": [
"CVE-2022-46641"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j8f-fjpj-x22v",
"modified": "2023-01-04T18:30:59Z",
"modified": "2025-04-15T06:30:34Z",
"published": "2022-12-23T21:30:19Z",
"aliases": [
"CVE-2022-46568"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46568"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/B1SZP0aIo"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetSysEmailSettings"
},
{
"type": "WEB",
"url": "https://hackmd.io/@0dayResearch/B1SZP0aIo"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59gg-pj3q-72g8",
"modified": "2023-01-04T21:30:19Z",
"modified": "2025-04-15T06:30:33Z",
"published": "2022-12-23T21:30:19Z",
"aliases": [
"CVE-2022-46563"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46563"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/HkDzZLCUo"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetDynamicDNSSettings"
},
{
"type": "WEB",
"url": "https://hackmd.io/@0dayResearch/HkDzZLCUo"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62xc-g7hf-p457",
"modified": "2022-12-31T00:30:23Z",
"modified": "2025-04-15T06:30:33Z",
"published": "2022-12-23T15:30:24Z",
"aliases": [
"CVE-2022-46642"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6m47-c6q4-33vq",
"modified": "2023-01-04T21:30:19Z",
"modified": "2025-04-15T06:30:33Z",
"published": "2022-12-23T21:30:19Z",
"aliases": [
"CVE-2022-46561"
@@ -19,6 +19,22 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46561"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWanSettings_L2TP"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWanSettings_PPPoE"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWanSettings_PPTP"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/ry55QVQvj"
},
{
"type": "WEB",
"url": "https://hackmd.io/@0dayResearch/SetWanSettings_L2TP"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c4m-cp34-4f9r",
"modified": "2023-01-04T18:30:58Z",
"modified": "2025-04-15T06:30:34Z",
"published": "2022-12-23T21:30:19Z",
"aliases": [
"CVE-2022-46570"
@@ -19,6 +19,22 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46570"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWan3Settings_l2tp"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWan3Settings_pppoe"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWan3Settings_pptp"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/r1zsTSmDs"
},
{
"type": "WEB",
"url": "https://hackmd.io/@0dayResearch/SetWan3Settings_l2tp"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2f3-jpg6-w3c6",
"modified": "2023-01-04T18:30:58Z",
"modified": "2025-04-15T06:30:34Z",
"published": "2022-12-23T21:30:19Z",
"aliases": [
"CVE-2022-46569"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46569"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWLanRadioSecurity"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/r1R6sWRUs"
},
{
"type": "WEB",
"url": "https://hackmd.io/@0dayResearch/SetWLanRadioSecurity"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jcw4-9ccq-g3rh",
"modified": "2022-12-30T18:30:44Z",
"modified": "2025-04-15T06:30:33Z",
"published": "2022-12-23T18:30:41Z",
"aliases": [
"CVE-2022-47938"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8ph-fr33-7cmg",
"modified": "2023-03-03T21:30:17Z",
"modified": "2025-04-15T06:30:33Z",
"published": "2022-12-23T21:30:19Z",
"aliases": [
"CVE-2022-46560"
@@ -19,6 +19,22 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46560"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWan2Settings_l2tp"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWan2Settings_pppoe"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetWan2Settings_pptp"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/rkXr4BQPi"
},
{
"type": "WEB",
"url": "https://hackmd.io/@0dayResearch/SetWan2Settings_l2tp"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxrm-98h4-c857",
"modified": "2023-01-04T21:30:19Z",
"modified": "2025-04-15T06:30:33Z",
"published": "2022-12-23T21:30:19Z",
"aliases": [
"CVE-2022-46562"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46562"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/B1C9jeXDi"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetQuickVPNSettings_PSK"
},
{
"type": "WEB",
"url": "https://hackmd.io/@0dayResearch/B1C9jeXDi"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xf9q-jgmw-h653",
"modified": "2023-01-04T18:31:00Z",
"modified": "2025-04-15T06:30:33Z",
"published": "2022-12-23T21:30:19Z",
"aliases": [
"CVE-2022-46566"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46566"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SetQuickVPNSettings_Password"
},
{
"type": "WEB",
"url": "https://hackmd.io/%400dayResearch/SyhDme7wo"
},
{
"type": "WEB",
"url": "https://hackmd.io/@0dayResearch/SetQuickVPNSettings_Password"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24vc-7q35-w5rv",
"modified": "2025-04-15T06:30:34Z",
"published": "2025-04-15T06:30:34Z",
"aliases": [
"CVE-2024-13207"
],
"details": "The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13207"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/c3e27fa2-b6dd-48eb-83ec-99dc034eff38"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-15T06:15:42Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6975-j4h6-fxff",
"modified": "2025-04-15T06:30:34Z",
"published": "2025-04-15T06:30:34Z",
"aliases": [
"CVE-2025-2225"
],
"details": "The Responsive Addons for Elementor Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rael_title_tag' parameter in all versions up to, and including, 1.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 1.6.9.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2225"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/responsive-addons-for-elementor/trunk/includes/widgets-manager/widgets/class-responsive-addons-for-elementor-icon-box.php#L2499"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3261241"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3263280"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f5ace7fb-530e-4a69-bbf7-e2c66491dd75?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-15T06:15:43Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j7px-pvwg-2r3m",
"modified": "2025-04-15T06:30:34Z",
"published": "2025-04-15T06:30:34Z",
"aliases": [
"CVE-2025-29984"
],
"details": "Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29984"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000299528/dsa-2025-151"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-15T04:15:36Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jcc3-vmjf-jfhj",
"modified": "2025-04-15T06:30:34Z",
"published": "2025-04-15T06:30:34Z",
"aliases": [
"CVE-2024-13610"
],
"details": "The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13610"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/85229528-1110-4d45-b972-8bbcba003a1f"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-15T06:15:43Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mwmr-r556-9837",
"modified": "2025-04-15T06:30:34Z",
"published": "2025-04-15T06:30:34Z",
"aliases": [
"CVE-2025-29983"
],
"details": "Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29983"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000299528/dsa-2025-151"
}
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-15T04:15:36Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcwj-m6p3-w8x3",
"modified": "2025-04-15T06:30:34Z",
"published": "2025-04-15T06:30:34Z",
"aliases": [
"CVE-2025-32993"
],
"details": "Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32993"
},
{
"type": "WEB",
"url": "https://nav1n.medium.com/sql-injection-in-vision-helpdesk-tools-a83dfc27f3ab"
},
{
"type": "WEB",
"url": "https://www.visionhelpdesk.com/vision-helpdesk-v5-7-0-stable-version-released.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-15T06:15:43Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfh5-gx7w-h7v7",
"modified": "2025-04-15T06:30:34Z",
"published": "2025-04-15T06:30:34Z",
"aliases": [
"CVE-2025-3576"
],
"details": "A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3576"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-3576"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359465"
}
],
"database_specific": {
"cwe_ids": [
"CWE-328"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-15T06:15:44Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rrj2-ph5q-jxw2",
"modified": "2025-04-15T06:30:34Z",
"published": "2025-04-15T06:30:34Z",
"aliases": [
"CVE-2025-3573"
],
"details": "Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3573"
},
{
"type": "WEB",
"url": "https://github.com/jquery-validation/jquery-validation/pull/2462"
},
{
"type": "WEB",
"url": "https://github.com/jquery-validation/jquery-validation/commit/7a490d8f39bd988027568ddcf51755e1f4688902"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-JS-JQUERYVALIDATION-5952285"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-15T05:15:31Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-whpg-7794-8rqm",
"modified": "2025-04-15T06:30:34Z",
"published": "2025-04-15T06:30:34Z",
"aliases": [
"CVE-2025-3622"
],
"details": "A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3622"
},
{
"type": "WEB",
"url": "https://github.com/xorbitsai/inference/issues/3190"
},
{
"type": "WEB",
"url": "https://github.com/xorbitsai/inference/issues/3190#issuecomment-2783462266"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.304679"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.304679"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.552245"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-15T06:15:44Z"
}
}