mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-r6j6-xp6q-c876",
|
||||
"modified": "2022-04-13T00:01:07Z",
|
||||
"modified": "2025-04-25T18:31:01Z",
|
||||
"published": "2022-02-22T00:00:22Z",
|
||||
"aliases": [
|
||||
"CVE-2022-0564"
|
||||
|
||||
@@ -25,7 +25,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-94"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3vg4-f6rw-v3x2",
|
||||
"modified": "2022-11-30T21:30:22Z",
|
||||
"modified": "2025-04-25T18:31:01Z",
|
||||
"published": "2022-11-25T18:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2022-23044"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c4w8-pfrf-hc8p",
|
||||
"modified": "2022-11-30T21:30:22Z",
|
||||
"modified": "2025-04-25T18:31:01Z",
|
||||
"published": "2022-11-25T06:30:22Z",
|
||||
"aliases": [
|
||||
"CVE-2022-36133"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c9xc-qcg9-c8hr",
|
||||
"modified": "2022-11-30T06:30:26Z",
|
||||
"modified": "2025-04-25T18:31:04Z",
|
||||
"published": "2022-11-29T06:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-42109"
|
||||
@@ -23,6 +23,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/PuneethReddyHC/online-shopping-system-advanced"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://grimthereaperteam.medium.com/online-shopping-system-advanced-sql-injection-at-product-php-c55c435c35c2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://medium.com/%40grimthereaperteam/online-shopping-system-advanced-sql-injection-at-product-php-c55c435c35c2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://medium.com/@grimthereaperteam/online-shopping-system-advanced-sql-injection-at-product-php-c55c435c35c2"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fp36-pmr8-vj9p",
|
||||
"modified": "2022-11-30T06:30:27Z",
|
||||
"modified": "2025-04-25T18:31:03Z",
|
||||
"published": "2022-11-28T15:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2022-3848"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hgwc-78jr-63c3",
|
||||
"modified": "2022-11-30T06:30:27Z",
|
||||
"modified": "2025-04-25T18:31:02Z",
|
||||
"published": "2022-11-28T15:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2022-3768"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pffr-gxw6-r2q7",
|
||||
"modified": "2022-11-30T00:30:37Z",
|
||||
"modified": "2025-04-25T18:31:02Z",
|
||||
"published": "2022-11-25T18:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2022-37720"
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-284",
|
||||
"CWE-287"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wxc6-2xqr-q2pg",
|
||||
"modified": "2022-11-29T21:30:26Z",
|
||||
"modified": "2025-04-25T18:31:01Z",
|
||||
"published": "2022-11-25T06:30:22Z",
|
||||
"aliases": [
|
||||
"CVE-2022-2721"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2x7c-w8p7-47f7",
|
||||
"modified": "2024-12-26T21:30:36Z",
|
||||
"modified": "2025-04-25T18:31:10Z",
|
||||
"published": "2024-12-25T18:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-56430"
|
||||
@@ -30,6 +30,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openfheorg/openfhe-development/releases/tag/v1.2.3"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2025/04/25/3"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8xp8-gmmj-xc8w",
|
||||
"modified": "2024-12-31T21:30:45Z",
|
||||
"modified": "2025-04-25T18:31:10Z",
|
||||
"published": "2024-12-25T18:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-56431"
|
||||
@@ -30,6 +30,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/xiph/theora/blob/7180717276af1ebc7da15c83162d6c5d6203aabf/lib/huffdec.c#L193"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2025/04/25/4"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2q5p-jwm7-4gq8",
|
||||
"modified": "2025-04-25T18:31:11Z",
|
||||
"published": "2025-04-25T18:31:11Z",
|
||||
"aliases": [
|
||||
"CVE-2021-32601"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32601"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-25T16:15:21Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2ww5-c4rg-76jh",
|
||||
"modified": "2025-04-25T18:31:11Z",
|
||||
"published": "2025-04-25T18:31:11Z",
|
||||
"aliases": [
|
||||
"CVE-2025-2069"
|
||||
],
|
||||
"details": "A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2069"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.filez.com/securityPolicy/2.html?1744703100"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-25T16:15:26Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-58xr-825m-v3pq",
|
||||
"modified": "2025-04-25T18:31:12Z",
|
||||
"published": "2025-04-25T18:31:12Z",
|
||||
"aliases": [
|
||||
"CVE-2025-2070"
|
||||
],
|
||||
"details": "An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2070"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.filez.com/securityPolicy/2.html?1744703100"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-611"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-25T16:15:26Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6mpj-6mgp-p7v6",
|
||||
"modified": "2025-04-25T18:31:11Z",
|
||||
"published": "2025-04-25T18:31:11Z",
|
||||
"aliases": [
|
||||
"CVE-2025-2068"
|
||||
],
|
||||
"details": "An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2068"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.filez.com/securityPolicy/2.html?1744703100"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-601"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-25T16:15:25Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7885-whv3-46f6",
|
||||
"modified": "2025-04-25T18:31:12Z",
|
||||
"published": "2025-04-25T18:31:12Z",
|
||||
"aliases": [
|
||||
"CVE-2025-25775"
|
||||
],
|
||||
"details": "Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25775"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://codeastro.com/bus-ticket-booking-system-in-php-codeigniter-with-source-code"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/arunmodi/Vulnerability-Research/tree/main/CVE-2025-25775"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-25T17:15:18Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-794f-v4rm-x7r5",
|
||||
"modified": "2025-04-25T03:30:33Z",
|
||||
"modified": "2025-04-25T18:31:10Z",
|
||||
"published": "2025-04-11T09:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3512"
|
||||
@@ -38,6 +38,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2025/04/25/1"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2025/04/25/2"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7g9q-ww3r-j77g",
|
||||
"modified": "2025-04-25T18:31:10Z",
|
||||
"published": "2025-04-17T18:31:22Z",
|
||||
"aliases": [
|
||||
"CVE-2025-43015"
|
||||
],
|
||||
"details": "In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43015"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.jetbrains.com/privacy-security/issues-fixed"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-1188"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-17T16:16:00Z"
|
||||
}
|
||||
}
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-99q6-5j8j-4wv8",
|
||||
"modified": "2025-04-24T21:31:48Z",
|
||||
"modified": "2025-04-25T18:31:10Z",
|
||||
"published": "2025-04-24T21:31:48Z",
|
||||
"aliases": [
|
||||
"CVE-2025-29529"
|
||||
],
|
||||
"details": "ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -24,8 +29,10 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"cwe_ids": [
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-24T21:15:24Z"
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user