Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-05-23 15:32:51 +00:00
parent e23db49608
commit a254210027
163 changed files with 5269 additions and 29 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gmg8-593g-7mv3",
"modified": "2025-04-18T18:34:17Z",
"modified": "2025-05-23T15:31:06Z",
"published": "2025-04-09T12:30:24Z",
"aliases": [
"CVE-2025-31672"
@@ -56,6 +56,10 @@
"type": "WEB",
"url": "https://lists.apache.org/thread/k14w8vcjqy4h34hh5kzldko78kpylkq5"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250523-0004"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/08/2"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jw74-jmpx-mj4j",
"modified": "2024-03-15T15:30:43Z",
"modified": "2025-05-23T15:31:03Z",
"published": "2024-03-15T15:30:43Z",
"aliases": [
"CVE-2024-25934"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade allows Stored XSS.This issue affects FormFacade: from n/a through 1.0.0.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade allows Stored XSS.This issue affects FormFacade: from n/a through 1.0.0.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7pq-vg76-qwqx",
"modified": "2024-10-30T15:30:46Z",
"modified": "2025-05-23T15:31:04Z",
"published": "2024-10-29T03:31:06Z",
"aliases": [
"CVE-2024-50083"
@@ -42,6 +42,10 @@
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/db04d1848777ae52a7ab93c4591e7c0bf8f55fb4"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250523-0010"
}
],
"database_specific": {
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vg86-8433-4hr2",
"modified": "2025-01-29T06:31:50Z",
"modified": "2025-05-23T15:31:05Z",
"published": "2025-01-29T06:31:50Z",
"aliases": [
"CVE-2025-0804"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-65rj-829h-6g8x",
"modified": "2025-02-04T15:31:37Z",
"modified": "2025-05-23T15:31:05Z",
"published": "2025-02-04T15:31:37Z",
"aliases": [
"CVE-2025-0825"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://github.com/yhirose/cpp-httplib/commit/9c36aae4b73e2b6e493f4133e4173103c9266289"
},
{
"type": "WEB",
"url": "https://advisory.checkmarx.net/advisory/CVE-2025-0825"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqj4-fp95-jqxq",
"modified": "2025-05-21T00:30:23Z",
"modified": "2025-05-23T15:31:05Z",
"published": "2025-02-10T18:30:46Z",
"aliases": [
"CVE-2024-12243"
@@ -46,6 +46,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00027.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250523-0002"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j3qr-8f3v-fgjj",
"modified": "2025-05-21T00:30:22Z",
"modified": "2025-05-23T15:31:05Z",
"published": "2025-02-10T18:30:47Z",
"aliases": [
"CVE-2024-12133"
@@ -47,6 +47,10 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00025.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250523-0003"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/02/06/6"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25wq-m5r4-rrm3",
"modified": "2025-05-23T15:31:09Z",
"published": "2025-05-23T15:31:09Z",
"aliases": [
"CVE-2025-31049"
],
"details": "Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31049"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/theme/dash/vulnerability/wordpress-dash-1-3-php-object-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T13:15:25Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2659-8m74-4v6x",
"modified": "2025-05-23T15:31:10Z",
"published": "2025-05-23T15:31:10Z",
"aliases": [
"CVE-2025-32289"
],
"details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Yozi allows PHP Local File Inclusion. This issue affects Yozi: from n/a through 2.0.52.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32289"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/theme/yozi/vulnerability/wordpress-yozi-2-0-52-local-file-inclusion-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-98"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T13:15:29Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2963-8wvc-3fv3",
"modified": "2025-05-23T15:31:15Z",
"published": "2025-05-23T15:31:15Z",
"aliases": [
"CVE-2025-47673"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.16.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47673"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/arconix-shortcodes/vulnerability/wordpress-arconix-shortcodes-plugin-2-1-16-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T13:15:42Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2g6j-8hm3-67hp",
"modified": "2025-05-23T15:31:10Z",
"published": "2025-05-23T15:31:10Z",
"aliases": [
"CVE-2025-39485"
],
"details": "Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39485"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/theme/grandtour/vulnerability/wordpress-grandtour-theme-5-5-1-php-object-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T13:15:30Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2gf3-v8px-49h6",
"modified": "2025-05-23T15:31:11Z",
"published": "2025-05-23T15:31:11Z",
"aliases": [
"CVE-2025-39506"
],
"details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core allows PHP Local File Inclusion. This issue affects Nasa Core: from n/a through 6.3.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39506"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/nasa-core/vulnerability/wordpress-nasa-core-plugin-6-3-2-local-file-inclusion-vulnerability-2?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-98"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T13:15:32Z"
}
}
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2rcx-2829-7fg5",
"modified": "2025-05-23T15:31:09Z",
"published": "2025-05-23T15:31:09Z",
"aliases": [
"CVE-2025-31069"
],
"details": "Deserialization of Untrusted Data vulnerability in themeton HotStar Multi-Purpose Business Theme allows Object Injection. This issue affects HotStar Multi-Purpose Business Theme: from n/a through 1.4.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31069"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/theme/hotstar/vulnerability/wordpress-hotstar-multi-purpose-business-theme-1-4-php-object-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T13:15:26Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2rgj-5hr4-v9vp",
"modified": "2025-05-23T15:31:14Z",
"published": "2025-05-23T15:31:14Z",
"aliases": [
"CVE-2025-47619"
],
"details": "Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Path Traversal. This issue affects 6Storage Rentals: from n/a through 2.19.4.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47619"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/6storage-rentals/vulnerability/wordpress-6storage-rentals-2-19-3-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T13:15:41Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2v3m-6ccx-2995",
"modified": "2025-05-23T15:31:14Z",
"published": "2025-05-23T15:31:14Z",
"aliases": [
"CVE-2025-47575"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 92.0.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47575"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/school-management/vulnerability/wordpress-school-management-plugin-92-0-0-sql-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T13:15:40Z"
}
}

Some files were not shown because too many files have changed in this diff Show More