Publish Advisories

GHSA-qhw8-gxv4-588x
GHSA-5j47-gwc2-fhfc
GHSA-3c6p-c4v9-m5mw
GHSA-3h49-gmxg-3c7g
GHSA-3xfr-5qpm-hvr4
GHSA-445m-27cf-gr3x
GHSA-4w9g-4h2x-7qxq
GHSA-cf79-3x47-jx24
GHSA-cjfc-vqf6-fvgw
GHSA-fgvj-q3hx-cpwr
GHSA-g69v-xr79-fx7w
GHSA-gpg3-h2f7-7hcx
GHSA-h4g8-pvpv-p57j
GHSA-qf47-6jwc-r2c7
GHSA-qhg4-2m23-3vvx
GHSA-v2rc-5jqj-6rmg
GHSA-vhr7-c3p5-qrf4
GHSA-vq95-6x79-qv8j
GHSA-x66m-vvh8-f89w
This commit is contained in:
advisory-database[bot]
2025-04-18 21:32:38 +00:00
parent ddb8104da9
commit cc88723097
19 changed files with 547 additions and 15 deletions
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3c6p-c4v9-m5mw",
"modified": "2025-04-18T21:31:20Z",
"published": "2025-04-18T21:31:20Z",
"aliases": [
"CVE-2024-57493"
],
"details": "An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockopt function.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57493"
},
{
"type": "WEB",
"url": "https://github.com/Marsman1996/pocs/tree/master/redox/CVE-2024-57493"
},
{
"type": "WEB",
"url": "https://gitlab.redox-os.org/redox-os/relibc/-/issues/201"
},
{
"type": "WEB",
"url": "https://gitlab.redox-os.org/redox-os/relibc/-/merge_requests/566"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T20:15:15Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3h49-gmxg-3c7g",
"modified": "2025-04-18T21:31:20Z",
"published": "2025-04-18T21:31:20Z",
"aliases": [
"CVE-2025-25983"
],
"details": "An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25983"
},
{
"type": "WEB",
"url": "https://github.com/vladko312/Research_v380_IP_camera"
},
{
"type": "WEB",
"url": "https://github.com/vladko312/Research_v380_IP_camera/blob/main/CVE-2025-25983.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-257"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T20:15:16Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3xfr-5qpm-hvr4",
"modified": "2025-04-18T21:31:21Z",
"published": "2025-04-18T21:31:21Z",
"aliases": [
"CVE-2024-53591"
],
"details": "An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53591"
},
{
"type": "WEB",
"url": "https://github.com/aljoharasubaie/CVE-2024-53591"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T21:15:43Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-445m-27cf-gr3x",
"modified": "2025-04-18T21:31:20Z",
"published": "2025-04-18T21:31:20Z",
"aliases": [
"CVE-2025-28197"
],
"details": "Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28197"
},
{
"type": "WEB",
"url": "https://gist.github.com/AndrewDzzz/f49e79b09ce0643ee1fc2a829e8875e0"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T20:15:16Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4w9g-4h2x-7qxq",
"modified": "2025-04-18T21:31:21Z",
"published": "2025-04-18T21:31:21Z",
"aliases": [
"CVE-2025-43903"
],
"details": "NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43903"
},
{
"type": "WEB",
"url": "https://gitlab.freedesktop.org/poppler/poppler/-/commit/f1b9c830f145a0042e853d6462b2f9ca4016c669"
}
],
"database_specific": {
"cwe_ids": [
"CWE-347"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T21:15:44Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cf79-3x47-jx24",
"modified": "2025-04-18T21:31:19Z",
"published": "2025-04-18T21:31:19Z",
"aliases": [
"CVE-2025-28355"
],
"details": "Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28355"
},
{
"type": "WEB",
"url": "https://github.com/Volmarg/personal-management-system/issues/149"
},
{
"type": "WEB",
"url": "https://github.com/Volmarg/personal-management-system"
},
{
"type": "WEB",
"url": "https://github.com/abbisQQ/CVE-2025-28355/tree/main"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T19:15:45Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjfc-vqf6-fvgw",
"modified": "2025-04-18T21:31:19Z",
"published": "2025-04-18T21:31:19Z",
"aliases": [
"CVE-2025-24914"
],
"details": "When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. - CVE-2025-24914",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24914"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2025-05"
}
],
"database_specific": {
"cwe_ids": [
"CWE-276"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T19:15:45Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fgvj-q3hx-cpwr",
"modified": "2025-04-18T15:31:37Z",
"modified": "2025-04-18T21:31:19Z",
"published": "2025-04-18T03:31:22Z",
"aliases": [
"CVE-2025-25427"
@@ -26,6 +26,10 @@
{
"type": "WEB",
"url": "https://github.com/slin99/2025-25427/blob/master/readme.md"
},
{
"type": "WEB",
"url": "https://www.tp-link.com/en/support/download/tl-wr841n/#Firmware"
}
],
"database_specific": {
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g69v-xr79-fx7w",
"modified": "2025-04-18T21:31:21Z",
"published": "2025-04-18T21:31:21Z",
"aliases": [
"CVE-2025-36625"
],
"details": "In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36625"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2025-05"
}
],
"database_specific": {
"cwe_ids": [
"CWE-117"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T20:15:16Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gpg3-h2f7-7hcx",
"modified": "2025-04-18T18:31:24Z",
"modified": "2025-04-18T21:31:19Z",
"published": "2025-04-18T18:31:24Z",
"aliases": [
"CVE-2025-29512"
],
"details": "Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T18:15:48Z"
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h4g8-pvpv-p57j",
"modified": "2025-04-18T21:31:21Z",
"published": "2025-04-18T21:31:21Z",
"aliases": [
"CVE-2025-3796"
],
"details": "A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us.php. The manipulation of the argument pagetitle/pagedes/email/mobnumber/timing leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3796"
},
{
"type": "WEB",
"url": "https://github.com/yaklang/IRifyScanResult/blob/main/Men-Salon-Management-System/sql_inject_in_contact_us.md"
},
{
"type": "WEB",
"url": "https://phpgurukul.com"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.305649"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.305649"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.554659"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T21:15:44Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qf47-6jwc-r2c7",
"modified": "2025-04-18T21:31:20Z",
"published": "2025-04-18T21:31:20Z",
"aliases": [
"CVE-2025-25985"
],
"details": "An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via the /mnt/mtd/mvconf/wifi.ini and /mnt/mtd/mvconf/user_info.ini components.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25985"
},
{
"type": "WEB",
"url": "https://github.com/vladko312/Research_v380_IP_camera"
},
{
"type": "WEB",
"url": "https://github.com/vladko312/Research_v380_IP_camera/blob/main/CVE-2025-25985.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-256"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T20:15:16Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qhg4-2m23-3vvx",
"modified": "2025-04-18T21:31:21Z",
"published": "2025-04-18T21:31:21Z",
"aliases": [
"CVE-2025-3795"
],
"details": "A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO Optimization Settings Section. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3795"
},
{
"type": "WEB",
"url": "https://github.com/daicuo/cms/issues/1"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.305648"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.305648"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.554639"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T20:15:16Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v2rc-5jqj-6rmg",
"modified": "2025-04-18T18:31:24Z",
"modified": "2025-04-18T21:31:19Z",
"published": "2025-04-18T18:31:24Z",
"aliases": [
"CVE-2025-29513"
],
"details": "Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T18:15:48Z"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vhr7-c3p5-qrf4",
"modified": "2025-04-18T21:31:21Z",
"published": "2025-04-18T21:31:21Z",
"aliases": [
"CVE-2025-29058"
],
"details": "An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29058"
},
{
"type": "WEB",
"url": "https://cdn.wjlin0.com/halo-img/74CMSv3.34.0%E5%AD%98%E5%9C%A8%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.zip"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T21:15:43Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vq95-6x79-qv8j",
"modified": "2025-04-18T18:31:24Z",
"modified": "2025-04-18T21:31:19Z",
"published": "2025-04-18T18:31:24Z",
"aliases": [
"CVE-2024-41447"
],
"details": "A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T17:15:33Z"
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x66m-vvh8-f89w",
"modified": "2025-04-18T21:31:20Z",
"published": "2025-04-18T21:31:20Z",
"aliases": [
"CVE-2025-25984"
],
"details": "An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25984"
},
{
"type": "WEB",
"url": "https://github.com/vladko312/Research_v380_IP_camera"
},
{
"type": "WEB",
"url": "https://github.com/vladko312/Research_v380_IP_camera/blob/main/CVE-2025-25984.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-259"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-18T20:15:16Z"
}
}