Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-05-19 18:32:43 +00:00
parent 6186cd05ea
commit b52c2e2a0e
103 changed files with 2643 additions and 70 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27mv-5vpc-8g53",
"modified": "2025-05-05T15:30:43Z",
"modified": "2025-05-19T18:30:34Z",
"published": "2023-08-04T00:30:15Z",
"aliases": [
"CVE-2023-38950"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://sploitus.com/exploit?id=PACKETSTORM:177859"
},
{
"type": "WEB",
"url": "https://www.fortinet.com/content/dam/fortinet/assets/reports/report-incident-response-middle-east.pdf"
},
{
"type": "WEB",
"url": "http://zkteco.com"
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rr36-3hq5-mqj8",
"modified": "2024-03-01T00:30:28Z",
"modified": "2025-05-19T18:30:35Z",
"published": "2024-03-01T00:30:28Z",
"aliases": [
"CVE-2024-2045"
],
"details": "Session version 1.17.5 allows obtaining internal application files and public\n\nfiles from the user's device without the user's consent. This is possible\n\nbecause the application is vulnerable to Local File Read via chat attachments.\n\n\n\n\n",
"details": "Session version 1.17.5 allows obtaining internal application files and public\n\nfiles from the user's device without the user's consent. This is possible\n\nbecause the application is vulnerable to Local File Read via chat attachments.",
"severity": [
{
"type": "CVSS_V3",
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qrvg-mg33-q843",
"modified": "2024-08-13T18:31:14Z",
"modified": "2025-05-19T18:30:36Z",
"published": "2024-08-12T15:30:53Z",
"aliases": [
"CVE-2024-27443"
@@ -26,6 +26,10 @@
{
"type": "WEB",
"url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P39#Security_Fixes"
},
{
"type": "WEB",
"url": "https://www.welivesecurity.com/en/eset-research/operation-roundpress"
}
],
"database_specific": {
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27mf-h76r-wrj9",
"modified": "2025-05-19T18:30:46Z",
"published": "2025-05-19T18:30:46Z",
"aliases": [
"CVE-2025-31262"
],
"details": "A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to modify protected parts of the file system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31262"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/122066"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/122068"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/122071"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/122072"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/122073"
}
],
"database_specific": {
"cwe_ids": [
"CWE-732"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T16:15:29Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-292v-wgjp-vm43",
"modified": "2025-05-19T18:30:48Z",
"published": "2025-05-19T18:30:47Z",
"aliases": [
"CVE-2025-26892"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26892"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/theme/celestial-aura/vulnerability/wordpress-celestial-aura-plugin-2-2-arbitrary-file-upload-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T18:15:28Z"
}
}
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2m98-w299-f59w",
"modified": "2025-05-19T18:30:47Z",
"published": "2025-05-19T18:30:47Z",
"aliases": [
"CVE-2025-39353"
],
"details": "Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39353"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/theme/grandrestaurant/vulnerability/wordpress-grand-restaurant-wordpress-theme-7-0-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T17:15:25Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qw9-5pj2-hf6h",
"modified": "2025-05-19T18:30:48Z",
"published": "2025-05-19T18:30:48Z",
"aliases": [
"CVE-2025-39412"
],
"details": "Missing Authorization vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.10.8.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39412"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/master-slider/vulnerability/wordpress-master-slider-plugin-3-10-7-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T18:15:29Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2r7h-jv72-f7xp",
"modified": "2025-05-19T18:30:47Z",
"published": "2025-05-19T18:30:47Z",
"aliases": [
"CVE-2025-39394"
],
"details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Solid Plugins AnalyticsWP allows Retrieve Embedded Sensitive Data.This issue affects AnalyticsWP: from n/a through 2.1.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39394"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/analyticswp/vulnerability/wordpress-analyticswp-plugin-2-1-2-sensitive-data-exposure-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-497"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T17:15:27Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3349-q488-4m7r",
"modified": "2025-05-19T18:30:46Z",
"published": "2025-05-19T18:30:46Z",
"aliases": [
"CVE-2025-23979"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duwasai Flashy allows Reflected XSS.This issue affects Flashy: from n/a through 1.2.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23979"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/theme/flashy/vulnerability/wordpress-flashy-theme-1-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T16:15:27Z"
}
}
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37xj-x86x-8h3f",
"modified": "2025-05-19T18:30:48Z",
"published": "2025-05-19T18:30:48Z",
"aliases": [
"CVE-2025-43834"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tox82 cookieBAR allows Stored XSS.This issue affects cookieBAR: from n/a through 1.7.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43834"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/cookiebar/vulnerability/wordpress-cookiebar-plugin-1-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T18:15:30Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f4g-72qh-pgc7",
"modified": "2025-05-19T18:30:47Z",
"published": "2025-05-19T18:30:47Z",
"aliases": [
"CVE-2025-39376"
],
"details": "Missing Authorization vulnerability in QuanticaLabs Car Park Booking System for WordPress.This issue affects Car Park Booking System for WordPress: from n/a through 2.6.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39376"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/car-park-booking-system-for-wordpress/vulnerability/wordpress-car-park-booking-system-for-wordpress-plugin-2-6-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T17:15:26Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3gx9-8889-ccm7",
"modified": "2025-05-19T15:31:00Z",
"modified": "2025-05-19T18:30:45Z",
"published": "2025-05-19T15:31:00Z",
"aliases": [
"CVE-2025-30072"
],
"details": "Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-294"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T15:15:23Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3hhf-g967-wcf6",
"modified": "2025-05-19T18:30:47Z",
"published": "2025-05-19T18:30:46Z",
"aliases": [
"CVE-2025-26867"
],
"details": "Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n/a through 1.0.11.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26867"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/theme/bulk/vulnerability/wordpress-bulk-theme-1-0-11-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T17:15:23Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vpx-xc92-826m",
"modified": "2025-05-19T18:30:47Z",
"published": "2025-05-19T18:30:47Z",
"aliases": [
"CVE-2025-39370"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cnilsson iCafe Library allows SQL Injection.This issue affects iCafe Library: from n/a through 1.8.3.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39370"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/icafe-library/vulnerability/wordpress-icafe-library-plugin-1-8-3-sql-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T17:15:25Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-43hr-6fp9-6wgg",
"modified": "2025-05-19T15:31:00Z",
"modified": "2025-05-19T18:30:45Z",
"published": "2025-05-19T15:31:00Z",
"aliases": [
"CVE-2024-55063"
],
"details": "Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code via the (1) lang parameter to /international/keyboard/options; the (2) keyboard_layout or (3) keyboard_variant parameter to /international/settings/keyboard; the (4) timezone parameter to /international/settings/timezone.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T15:15:22Z"
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4ffv-mjwj-jpv4",
"modified": "2025-05-19T18:30:48Z",
"published": "2025-05-19T18:30:48Z",
"aliases": [
"CVE-2025-39460"
],
"details": "Missing Authorization vulnerability in ThimPress Eduma allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eduma: from n/a through 5.6.4.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39460"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/theme/eduma/vulnerability/wordpress-eduma-theme-5-6-4-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-19T18:15:29Z"
}
}

Some files were not shown because too many files have changed in this diff Show More