Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-03-19 21:32:19 +00:00
parent 97ecde4baa
commit c05c4115f5
102 changed files with 1063 additions and 246 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p3fp-8748-vqfq",
"modified": "2025-03-06T22:35:37Z",
"modified": "2025-03-19T21:30:45Z",
"published": "2025-03-06T21:31:26Z",
"aliases": [
"CVE-2025-26699"
@@ -90,6 +90,10 @@
"type": "WEB",
"url": "https://groups.google.com/g/django-announce"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00012.html"
},
{
"type": "WEB",
"url": "https://www.djangoproject.com/weblog/2025/mar/06/security-releases"
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78w8-55r3-m9mq",
"modified": "2022-01-20T00:02:12Z",
"modified": "2025-03-19T21:30:35Z",
"published": "2022-01-14T00:02:08Z",
"aliases": [
"CVE-2021-45422"
],
"details": "Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process \"count\" parameter via GET. No authentication is required.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45422"
},
{
"type": "WEB",
"url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2021-45422/RLM%2014.2%20Cross%20Site%20Scripting.txt"
},
{
"type": "WEB",
"url": "https://seclists.org/fulldisclosure/2022/Jan/31"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5p56-56jf-wfv2",
"modified": "2022-05-13T01:10:43Z",
"modified": "2025-03-19T21:30:35Z",
"published": "2022-05-13T01:10:43Z",
"aliases": [
"CVE-2017-12637"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8775-h79w-g4rq",
"modified": "2024-04-04T01:15:07Z",
"modified": "2025-03-19T21:30:35Z",
"published": "2022-05-24T16:50:08Z",
"aliases": [
"CVE-2019-13029"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13029"
},
{
"type": "WEB",
"url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2019-13029/REDCap%20Cross%20Site%20Scripting.txt"
},
{
"type": "WEB",
"url": "https://gitlab.com/snippets/1874216"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2cr-7p52-q7p6",
"modified": "2022-05-14T03:41:03Z",
"modified": "2025-03-19T21:30:34Z",
"published": "2022-05-14T03:41:03Z",
"aliases": [
"CVE-2018-6867"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://exploit-db.com/exploits/44171"
},
{
"type": "WEB",
"url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2018-6867/Alibaba%20Clone%20Script%201.0.2%20Cross%20Site%20Scripting.txt"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w832-4843-q4m8",
"modified": "2022-05-13T01:09:56Z",
"modified": "2025-03-19T21:30:35Z",
"published": "2022-05-13T01:09:56Z",
"aliases": [
"CVE-2019-1000018"
@@ -23,10 +23,26 @@
"type": "WEB",
"url": "https://esnet-security.github.io/vulnerabilities/20190115_rssh"
},
{
"type": "WEB",
"url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2021-33216%2CCVE-2019-1000018/CommScope%20Ruckus%20IoT%20Controller%201.7.1.0%20Undocumented%20Account.txt"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2019/01/msg00027.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HO3MDU3AH5SLYBKHH5PJ6PHC63ASIF42"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KR2OHTHMJVV4DO3HDRFQQZ5JENHDJQEN"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T42YYNWJZG422GATWAHAEK4A24OKY557"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HO3MDU3AH5SLYBKHH5PJ6PHC63ASIF42"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p5ph-q447-9jqq",
"modified": "2024-04-04T04:49:16Z",
"modified": "2025-03-19T21:30:37Z",
"published": "2023-06-14T00:30:41Z",
"aliases": [
"CVE-2023-33140"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33140"
},
{
"type": "WEB",
"url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2023-33140/Microsoft%20OneNote%20(Version%202305%20Build%2016.0.16501.20074)%2064-bit%20-%20Spoofing%20Vulnerability.txt"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33140"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjmv-6p6x-5mrf",
"modified": "2024-04-04T05:33:40Z",
"modified": "2025-03-19T21:30:37Z",
"published": "2023-07-06T19:24:10Z",
"aliases": [
"CVE-2022-27677"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-276"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cr3-7r4p-pwrg",
"modified": "2024-03-26T21:30:47Z",
"modified": "2025-03-19T21:30:38Z",
"published": "2024-03-26T21:30:47Z",
"aliases": [
"CVE-2023-47873"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.\n\n",
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-95cq-m3g2-g9qh",
"modified": "2024-03-27T06:30:33Z",
"modified": "2025-03-19T21:30:38Z",
"published": "2024-03-27T06:30:32Z",
"aliases": [
"CVE-2024-25920"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.3.4.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.3.4.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h882-2wqp-8p7h",
"modified": "2024-03-27T09:30:40Z",
"modified": "2025-03-19T21:30:39Z",
"published": "2024-03-27T09:30:40Z",
"aliases": [
"CVE-2024-29915"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Reflected XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.0.9.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Reflected XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.0.9.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcq9-8j5c-v9xw",
"modified": "2024-03-26T21:30:47Z",
"modified": "2025-03-19T21:30:38Z",
"published": "2024-03-26T21:30:47Z",
"aliases": [
"CVE-2023-47846"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Terry Lin WP Githuber MD.This issue affects WP Githuber MD: from n/a through 1.16.2.\n\n",
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Terry Lin WP Githuber MD.This issue affects WP Githuber MD: from n/a through 1.16.2.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phgj-f9rj-3h57",
"modified": "2024-03-26T06:30:53Z",
"modified": "2025-03-19T21:30:38Z",
"published": "2024-03-26T06:30:53Z",
"aliases": [
"CVE-2024-2888"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid Visual Drag and Drop Editor: from n/a through 1.26.2.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid Visual Drag and Drop Editor: from n/a through 1.26.2.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qrhf-rx22-ww4h",
"modified": "2024-03-29T18:30:43Z",
"modified": "2025-03-19T21:30:39Z",
"published": "2024-03-29T18:30:43Z",
"aliases": [
"CVE-2024-30454"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.\n\n",
"details": "Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvw8-hcw4-jwqp",
"modified": "2024-03-25T06:30:24Z",
"modified": "2025-03-19T21:30:38Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-1231"
],
"details": "The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-276"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32q4-6g3f-wq36",
"modified": "2024-05-14T18:30:51Z",
"modified": "2025-03-19T21:30:39Z",
"published": "2024-05-14T18:30:51Z",
"aliases": [
"CVE-2024-34811"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g7f-9v94-gj5g",
"modified": "2024-05-14T18:30:47Z",
"modified": "2025-03-19T21:30:39Z",
"published": "2024-05-14T18:30:47Z",
"aliases": [
"CVE-2024-32712"
],
"details": "Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.\n\n",
"details": "Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.",
"severity": [
{
"type": "CVSS_V3",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352",
"CWE-862"
],
"severity": "HIGH",

Some files were not shown because too many files have changed in this diff Show More