Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-05-23 18:33:45 +00:00
parent 533f76d56a
commit a715bb7be1
49 changed files with 481 additions and 73 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2v42-xp3j-47m4",
"modified": "2024-04-08T15:42:15Z",
"modified": "2025-05-23T18:32:28Z",
"published": "2024-04-06T12:30:56Z",
"aliases": [
"CVE-2024-3366"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/xuxueli/xxl-job/issues/3391"
},
{
"type": "WEB",
"url": "https://github.com/xuxueli/xxl-job/commit/e3b2e1234614195390f46e26c15cd4881bd4dbe3"
},
{
"type": "PACKAGE",
"url": "https://github.com/xuxueli/xxl-job"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86wj-xg3c-r8gx",
"modified": "2022-10-20T19:00:36Z",
"modified": "2025-05-23T18:31:51Z",
"published": "2022-10-17T19:00:24Z",
"aliases": [
"CVE-2022-3559"
@@ -27,6 +27,18 @@
"type": "WEB",
"url": "https://git.exim.org/exim.git/commit/4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIH4W5R7SHTUEQFWWKB4TUO5YFZX64KV"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMQ6OCKPNPBPSD37YR4FOWV2R54M2UEP"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WFHLZVHNNO2GWYP5EA4TZQZ5O4GVPARR"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EIH4W5R7SHTUEQFWWKB4TUO5YFZX64KV"
@@ -46,7 +58,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jcq6-47h7-2c66",
"modified": "2022-10-24T19:00:22Z",
"modified": "2025-05-23T18:31:52Z",
"published": "2022-10-21T12:00:17Z",
"aliases": [
"CVE-2022-3620"
@@ -23,6 +23,18 @@
"type": "WEB",
"url": "https://git.exim.org/exim.git/commit/12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/667V3ADXQ2MHUJMSXA3VZZEWLVSCIBEU"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIH4W5R7SHTUEQFWWKB4TUO5YFZX64KV"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XV2K2AWF62FSJ64B5CUZPFT4COK7P5PM"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/667V3ADXQ2MHUJMSXA3VZZEWLVSCIBEU"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35g3-5r8c-ffwf",
"modified": "2024-02-27T18:31:02Z",
"modified": "2025-05-23T18:31:52Z",
"published": "2024-02-27T18:31:02Z",
"aliases": [
"CVE-2024-25841"
],
"details": "In the module \"So Flexibilite\" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-27T17:15:12Z"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-401"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-238q-xvw6-rfhf",
"modified": "2025-01-31T18:31:05Z",
"modified": "2025-05-23T18:31:52Z",
"published": "2025-01-31T06:30:53Z",
"aliases": [
"CVE-2024-12872"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mrr-3jvw-jc5j",
"modified": "2025-01-31T06:30:52Z",
"modified": "2025-05-23T18:31:52Z",
"published": "2025-01-31T06:30:52Z",
"aliases": [
"CVE-2025-0470"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fqx-9j9h-4f77",
"modified": "2025-02-17T00:31:39Z",
"modified": "2025-05-23T18:31:54Z",
"published": "2025-02-17T00:31:39Z",
"aliases": [
"CVE-2025-22289"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rqp-q2jf-gm6h",
"modified": "2025-02-17T00:31:40Z",
"modified": "2025-05-23T18:31:54Z",
"published": "2025-02-17T00:31:40Z",
"aliases": [
"CVE-2025-26767"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cwqv-628v-v6fj",
"modified": "2025-02-04T12:30:58Z",
"modified": "2025-05-23T18:31:53Z",
"published": "2025-02-04T12:30:58Z",
"aliases": [
"CVE-2024-13733"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gqj7-345q-xx3j",
"modified": "2025-02-17T06:30:39Z",
"modified": "2025-05-23T18:31:54Z",
"published": "2025-02-17T06:30:39Z",
"aliases": [
"CVE-2025-0924"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352",
"CWE-79"
],
"severity": "MODERATE",
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wv32-c2xr-97ch",
"modified": "2025-02-17T00:31:39Z",
"modified": "2025-05-23T18:31:54Z",
"published": "2025-02-17T00:31:39Z",
"aliases": [
"CVE-2025-22284"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2h3c-3h32-6j65",
"modified": "2025-05-23T18:32:12Z",
"published": "2025-05-23T18:32:12Z",
"aliases": [
"CVE-2024-48704"
],
"details": "Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48704"
},
{
"type": "WEB",
"url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Medical%20Card%20Generation%20System/HTML%20Injection%28pagedes%29.pdf"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T16:15:24Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mx4-jrqf-62cp",
"modified": "2025-05-23T18:32:12Z",
"published": "2025-05-23T18:32:12Z",
"aliases": [
"CVE-2024-51099"
],
"details": "A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchdata parameter.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51099"
},
{
"type": "WEB",
"url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Medical%20Card%20Generation%20System/Reflected%20Cross-Site%20Scripting%20%28XSS%29-medical%20card%20details%20search.pdf"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T16:15:24Z"
}
}

Some files were not shown because too many files have changed in this diff Show More