mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-f82v-jwr5-mffw",
|
||||
"modified": "2025-03-24T14:40:22Z",
|
||||
"modified": "2025-03-28T15:31:53Z",
|
||||
"published": "2025-03-21T15:20:12Z",
|
||||
"aliases": [
|
||||
"CVE-2025-29927"
|
||||
@@ -121,6 +121,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/vercel/next.js/releases/tag/v13.5.9"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250328-0002"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vercel.com/changelog/vercel-firewall-proactively-protects-against-vulnerability-with-middleware"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3xjv-m925-6jcj",
|
||||
"modified": "2024-07-16T18:31:41Z",
|
||||
"modified": "2025-03-28T15:31:42Z",
|
||||
"published": "2022-02-17T00:00:27Z",
|
||||
"aliases": [
|
||||
"CVE-2021-3773"
|
||||
@@ -27,6 +27,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://citizenlab.ca/2024/07/vulnerabilities-in-vpns-paper-presented-at-the-privacy-enhancing-technologies-symposium-2024"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250328-0004"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.oracle.com/security-alerts/cpujul2022.html"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wc8w-gx27-xp92",
|
||||
"modified": "2022-10-14T12:00:16Z",
|
||||
"modified": "2025-03-28T15:31:42Z",
|
||||
"published": "2022-05-24T17:34:11Z",
|
||||
"aliases": [
|
||||
"CVE-2020-8745"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wrj6-35fr-8xw5",
|
||||
"modified": "2022-05-13T01:25:01Z",
|
||||
"modified": "2025-03-28T15:31:43Z",
|
||||
"published": "2022-05-13T01:25:01Z",
|
||||
"aliases": [
|
||||
"CVE-2016-9840"
|
||||
|
||||
@@ -26,7 +26,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-77"
|
||||
"CWE-77",
|
||||
"CWE-94"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -25,7 +25,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-404"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-76w4-2fg3-x9mc",
|
||||
"modified": "2023-02-08T03:30:26Z",
|
||||
"modified": "2025-03-28T15:31:44Z",
|
||||
"published": "2023-01-31T00:30:17Z",
|
||||
"aliases": [
|
||||
"CVE-2022-48176"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fm73-7fg4-q5w8",
|
||||
"modified": "2023-02-06T21:30:33Z",
|
||||
"modified": "2025-03-28T15:31:43Z",
|
||||
"published": "2023-01-30T09:30:40Z",
|
||||
"aliases": [
|
||||
"CVE-2023-22324"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-w496-f5jm-w9c3",
|
||||
"modified": "2023-02-06T21:30:33Z",
|
||||
"modified": "2025-03-28T15:31:43Z",
|
||||
"published": "2023-01-30T09:30:40Z",
|
||||
"aliases": [
|
||||
"CVE-2023-22332"
|
||||
|
||||
@@ -25,7 +25,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-269"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rh83-2fx8-8x6x",
|
||||
"modified": "2024-01-09T18:30:28Z",
|
||||
"modified": "2025-03-28T15:31:44Z",
|
||||
"published": "2024-01-09T18:30:28Z",
|
||||
"aliases": [
|
||||
"CVE-2024-20672"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20672"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250328-0006"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-37xw-rpjg-xxfx",
|
||||
"modified": "2024-05-14T18:30:54Z",
|
||||
"modified": "2025-03-28T15:31:50Z",
|
||||
"published": "2024-05-14T18:30:54Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4317"
|
||||
@@ -19,6 +19,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4317"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250328-0001"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.postgresql.org/support/security/CVE-2024-4317"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cwpg-qgc6-jxvq",
|
||||
"modified": "2024-08-21T15:30:49Z",
|
||||
"modified": "2025-03-28T15:31:50Z",
|
||||
"published": "2024-07-02T21:32:16Z",
|
||||
"aliases": [
|
||||
"CVE-2023-24531"
|
||||
@@ -38,6 +38,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pkg.go.dev/vuln/GO-2024-2962"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250328-0005"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -26,7 +26,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-285"
|
||||
"CWE-285",
|
||||
"CWE-862"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m366-8h8r-6fqr",
|
||||
"modified": "2025-02-19T00:31:16Z",
|
||||
"modified": "2025-03-28T15:31:50Z",
|
||||
"published": "2025-02-19T00:31:16Z",
|
||||
"aliases": [
|
||||
"CVE-2024-56171"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/828"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250328-0010"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2pvf-46qr-hp98",
|
||||
"modified": "2025-03-15T03:30:16Z",
|
||||
"modified": "2025-03-28T15:31:50Z",
|
||||
"published": "2025-03-15T03:30:16Z",
|
||||
"aliases": [
|
||||
"CVE-2025-1657"
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-39q9-q8cr-48r9",
|
||||
"modified": "2025-03-28T15:31:56Z",
|
||||
"published": "2025-03-28T15:31:56Z",
|
||||
"aliases": [
|
||||
"CVE-2025-2861"
|
||||
],
|
||||
"details": "SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is exchanged in unencrypted text. Since sensitive data such as credentials are exchanged, an attacker could obtain them and log in legitimately.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2861"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-319"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-03-28T14:15:21Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3rpf-hx7x-258c",
|
||||
"modified": "2025-03-28T15:31:57Z",
|
||||
"published": "2025-03-28T15:31:56Z",
|
||||
"aliases": [
|
||||
"CVE-2024-51624"
|
||||
],
|
||||
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-Já Pagamentos for WooCommerce allows Reflected XSS. This issue affects Já-Já Pagamentos for WooCommerce: from n/a through 1.3.0.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51624"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://patchstack.com/database/wordpress/plugin/wc-ja-ja-pagamentos-multicaixa-express/vulnerability/wordpress-ja-ja-pagamentos-for-woocommerce-plugin-1-3-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-03-28T15:15:45Z"
|
||||
}
|
||||
}
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-475h-5v9w-xfp6",
|
||||
"modified": "2025-03-28T06:30:27Z",
|
||||
"modified": "2025-03-28T15:31:55Z",
|
||||
"published": "2025-03-28T06:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2025-1762"
|
||||
],
|
||||
"details": "The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -21,7 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-03-28T06:15:32Z"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4mr4-q2q7-hmgc",
|
||||
"modified": "2025-03-15T06:30:32Z",
|
||||
"modified": "2025-03-28T15:31:51Z",
|
||||
"published": "2025-03-15T06:30:32Z",
|
||||
"aliases": [
|
||||
"CVE-2025-1667"
|
||||
@@ -30,7 +30,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-639"
|
||||
"CWE-639",
|
||||
"CWE-862"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user