Publish Advisories

GHSA-4q97-mrgv-92q2
GHSA-66gv-x64x-x377
GHSA-6j2q-c73v-97c5
GHSA-77wp-p4v3-xgj7
GHSA-8w6q-4mh2-p2gh
GHSA-9r89-rh23-vf6r
GHSA-qj62-4grm-wg6v
This commit is contained in:
advisory-database[bot]
2025-05-30 06:32:00 +00:00
parent ad061df9be
commit b0e6bcfcbf
7 changed files with 238 additions and 0 deletions
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4q97-mrgv-92q2",
"modified": "2025-05-30T06:30:24Z",
"published": "2025-05-30T06:30:24Z",
"aliases": [
"CVE-2025-44906"
],
"details": "jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44906"
},
{
"type": "WEB",
"url": "https://github.com/madao123123/crash_report/blob/main/jhead/jhead.md"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T04:15:46Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66gv-x64x-x377",
"modified": "2025-05-30T06:30:25Z",
"published": "2025-05-30T06:30:25Z",
"aliases": [
"CVE-2025-5259"
],
"details": "The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the align parameter in all versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5259"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/minimal-share-buttons/trunk/inc/class-minimal-share-buttons.php#L67"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3302704%40minimal-share-buttons&old=3074272%40minimal-share-buttons&sfp_email=&sfph_mail="
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/minimal-share-buttons/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7ac2ac7a-4cb5-4051-bec7-a22693c50915?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T06:15:28Z"
}
}
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6j2q-c73v-97c5",
"modified": "2025-05-30T06:30:25Z",
"published": "2025-05-30T06:30:25Z",
"aliases": [
"CVE-2025-41235"
],
"details": "Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41235"
},
{
"type": "WEB",
"url": "https://spring.io/security/cve-2025-41235"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T06:15:26Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77wp-p4v3-xgj7",
"modified": "2025-05-30T06:30:24Z",
"published": "2025-05-30T06:30:24Z",
"aliases": [
"CVE-2025-44904"
],
"details": "hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44904"
},
{
"type": "WEB",
"url": "https://github.com/madao123123/crash_report/blob/main/hdf5_poc/hdf5_poc1.md"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T04:15:32Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w6q-4mh2-p2gh",
"modified": "2025-05-30T06:30:25Z",
"published": "2025-05-30T06:30:25Z",
"aliases": [
"CVE-2025-4429"
],
"details": "The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4429"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/a487f5c9-7db6-4427-8d95-17acbfd49fd2"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T06:15:28Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9r89-rh23-vf6r",
"modified": "2025-05-30T06:30:24Z",
"published": "2025-05-30T06:30:24Z",
"aliases": [
"CVE-2025-44905"
],
"details": "hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44905"
},
{
"type": "WEB",
"url": "https://github.com/madao123123/crash_report/blob/main/hdf5_poc/hdf5_poc5.md"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T04:15:46Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qj62-4grm-wg6v",
"modified": "2025-05-30T06:30:25Z",
"published": "2025-05-30T06:30:25Z",
"aliases": [
"CVE-2025-4659"
],
"details": "The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4659"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3299864"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a99456c4-c828-4dc9-9375-8981eafbeb15?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-30T06:15:28Z"
}
}