Publish Advisories

GHSA-f326-p7mm-52h2
GHSA-j7g9-fcw9-wxcf
GHSA-j8q5-rwmr-9hg8
GHSA-x27v-rjqh-f4xc
GHSA-pjrv-5vw3-5frj
GHSA-frwq-jm7h-q2q2
GHSA-57qm-97m4-7q67
GHSA-5hfg-864g-w62r
GHSA-g533-46g7-g2f9
GHSA-rmf5-rhfv-3qrp
GHSA-39p5-3m6f-c8xp
GHSA-49v8-p6mm-3pfj
GHSA-5gwv-2q72-gxrm
GHSA-5prh-r43c-x8ww
GHSA-72xp-5wmc-q74j
GHSA-8h3c-wm8x-wcrq
GHSA-8w5r-w84g-hvww
GHSA-9pv7-g3rx-xpqw
GHSA-frqg-qr33-mvr2
GHSA-mrfj-vv5j-9gw5
GHSA-rpvv-rj3m-qqgx
GHSA-w73q-37g7-jp37
This commit is contained in:
advisory-database[bot]
2025-04-02 21:32:53 +00:00
parent aab51a08ef
commit bff721dcd8
22 changed files with 508 additions and 11 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f326-p7mm-52h2",
"modified": "2022-08-14T00:00:22Z",
"modified": "2025-04-02T21:30:41Z",
"published": "2022-08-11T00:00:15Z",
"aliases": [
"CVE-2021-33644"
@@ -19,6 +19,26 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33644"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j7g9-fcw9-wxcf",
"modified": "2022-08-14T00:00:22Z",
"modified": "2025-04-02T21:30:41Z",
"published": "2022-08-11T00:00:15Z",
"aliases": [
"CVE-2021-33643"
@@ -19,6 +19,26 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33643"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8q5-rwmr-9hg8",
"modified": "2022-12-28T06:30:18Z",
"modified": "2025-04-02T21:30:41Z",
"published": "2022-08-11T00:00:15Z",
"aliases": [
"CVE-2021-33645"
@@ -19,6 +19,26 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33645"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x27v-rjqh-f4xc",
"modified": "2022-12-28T06:30:18Z",
"modified": "2025-04-02T21:30:42Z",
"published": "2022-08-11T00:00:15Z",
"aliases": [
"CVE-2021-33646"
@@ -19,6 +19,26 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33646"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pjrv-5vw3-5frj",
"modified": "2022-12-29T21:30:30Z",
"modified": "2025-04-02T21:30:42Z",
"published": "2022-12-19T18:30:25Z",
"aliases": [
"CVE-2021-33640"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33640"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frwq-jm7h-q2q2",
"modified": "2024-08-01T15:31:26Z",
"modified": "2025-04-02T21:30:44Z",
"published": "2024-02-20T09:30:32Z",
"aliases": [
"CVE-2024-25974"
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g533-46g7-g2f9",
"modified": "2025-04-01T21:30:46Z",
"modified": "2025-04-02T21:30:49Z",
"published": "2025-03-26T18:30:50Z",
"aliases": [
"CVE-2025-2825"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://attackerkb.com/topics/k0EgiL9Psz/cve-2025-2825/rapid7-analysis"
},
{
"type": "WEB",
"url": "https://outpost24.com/blog/crushftp-auth-bypass-vulnerability"
},
{
"type": "WEB",
"url": "https://projectdiscovery.io/blog/crushftp-authentication-bypass"
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-39p5-3m6f-c8xp",
"modified": "2025-04-02T21:30:51Z",
"published": "2025-04-02T21:30:51Z",
"aliases": [
"CVE-2025-29063"
],
"details": "An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29063"
},
{
"type": "WEB",
"url": "https://www.yuque.com/jichujiliangdanwei/vwbq9e/grfgkm2kvk6btwbp"
},
{
"type": "WEB",
"url": "https://www.yuque.com/jichujiliangdanwei/vwbq9e/ux1426h170rhgfn7"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:32Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-49v8-p6mm-3pfj",
"modified": "2025-04-02T21:30:51Z",
"published": "2025-04-02T21:30:51Z",
"aliases": [
"CVE-2025-29085"
],
"details": "SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29085"
},
{
"type": "WEB",
"url": "https://gist.github.com/Cafe-Tea/bcef0d7a2bdb5ec8e0d69de852fdc900"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:32Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gwv-2q72-gxrm",
"modified": "2025-04-02T21:30:51Z",
"published": "2025-04-02T21:30:51Z",
"aliases": [
"CVE-2025-2704"
],
"details": "OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2704"
},
{
"type": "WEB",
"url": "https://community.openvpn.net/openvpn/wiki/CVE-2025-2704"
}
],
"database_specific": {
"cwe_ids": [
"CWE-754"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:32Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5prh-r43c-x8ww",
"modified": "2025-04-02T21:30:50Z",
"published": "2025-04-02T21:30:50Z",
"aliases": [
"CVE-2025-22923"
],
"details": "An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22923"
},
{
"type": "WEB",
"url": "https://github.com/OS4ED/openSIS-Classic"
},
{
"type": "WEB",
"url": "https://github.com/esusalla/vulnerability-research/tree/main/CVE-2025-22923"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:32Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-72xp-5wmc-q74j",
"modified": "2025-04-02T21:30:51Z",
"published": "2025-04-02T21:30:51Z",
"aliases": [
"CVE-2025-22925"
],
"details": "OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22925"
},
{
"type": "WEB",
"url": "https://github.com/OS4ED/openSIS-Classic"
},
{
"type": "WEB",
"url": "https://github.com/esusalla/vulnerability-research/tree/main/CVE-2025-22925"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:32Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h3c-wm8x-wcrq",
"modified": "2025-04-02T21:30:49Z",
"published": "2025-04-02T21:30:49Z",
"aliases": [
"CVE-2024-38392"
],
"details": "Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38392"
},
{
"type": "WEB",
"url": "https://docs.pexip.com/admin/security_bulletins.htm"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:31Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w5r-w84g-hvww",
"modified": "2025-04-02T21:30:51Z",
"published": "2025-04-02T21:30:51Z",
"aliases": [
"CVE-2025-3118"
],
"details": "A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3118"
},
{
"type": "WEB",
"url": "https://github.com/byxs0x0/SQL/blob/main/SQL3.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.303009"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.303009"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.524985"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:33Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pv7-g3rx-xpqw",
"modified": "2025-04-02T21:30:51Z",
"published": "2025-04-02T21:30:51Z",
"aliases": [
"CVE-2025-30080"
],
"details": "Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30080"
},
{
"type": "WEB",
"url": "https://docs.pexip.com/admin/security_bulletins.htm"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:33Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frqg-qr33-mvr2",
"modified": "2025-04-02T21:30:51Z",
"published": "2025-04-02T21:30:51Z",
"aliases": [
"CVE-2025-29719"
],
"details": "SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29719"
},
{
"type": "WEB",
"url": "https://github.com/sw8y/vulnerability_research/blob/main/CVE-2025-29719/CVE-2025-29719.md"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com/php/17847/employee-management-system-using-php-and-mysql-source-code.html"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:32Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mrfj-vv5j-9gw5",
"modified": "2025-04-02T21:30:50Z",
"published": "2025-04-02T21:30:50Z",
"aliases": [
"CVE-2025-22924"
],
"details": "OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22924"
},
{
"type": "WEB",
"url": "https://github.com/OS4ED/openSIS-Classic"
},
{
"type": "WEB",
"url": "https://github.com/esusalla/vulnerability-research/tree/main/CVE-2025-22924"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:32Z"
}
}

Some files were not shown because too many files have changed in this diff Show More