Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-04-09 18:32:33 +00:00
parent 5390231f45
commit d91a29078e
141 changed files with 4326 additions and 31 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47xh-88vf-mqw7",
"modified": "2023-01-18T15:30:30Z",
"modified": "2025-04-09T18:30:38Z",
"published": "2023-01-10T21:30:26Z",
"aliases": [
"CVE-2022-45165"
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-284"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5qg-593p-j5gq",
"modified": "2023-01-14T06:30:29Z",
"modified": "2025-04-09T18:30:38Z",
"published": "2023-01-10T21:30:26Z",
"aliases": [
"CVE-2022-45167"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jc4j-5j4g-r9cv",
"modified": "2023-01-14T06:30:29Z",
"modified": "2025-04-09T18:30:38Z",
"published": "2023-01-10T21:30:26Z",
"aliases": [
"CVE-2022-45164"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vfm9-f37f-c9j3",
"modified": "2023-01-14T06:30:29Z",
"modified": "2025-04-09T18:30:38Z",
"published": "2023-01-10T21:30:26Z",
"aliases": [
"CVE-2022-45166"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3w7c-xcfc-fcwc",
"modified": "2024-03-20T15:32:48Z",
"modified": "2025-04-09T18:30:39Z",
"published": "2024-03-20T15:32:48Z",
"aliases": [
"CVE-2024-1325"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4q5q-v9v4-9c33",
"modified": "2024-03-28T15:30:33Z",
"modified": "2025-04-09T18:30:40Z",
"published": "2024-03-28T15:30:33Z",
"aliases": [
"CVE-2024-0259"
],
"details": "Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.\n\n",
"details": "Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59hg-3x57-2mwj",
"modified": "2024-03-29T15:30:28Z",
"modified": "2025-04-09T18:30:40Z",
"published": "2024-03-29T15:30:28Z",
"aliases": [
"CVE-2024-30458"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS WooCommerce Currency Switcher.This issue affects WOOCS WooCommerce Currency Switcher: from n/a through 1.4.1.7.\n\n",
"details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS WooCommerce Currency Switcher.This issue affects WOOCS WooCommerce Currency Switcher: from n/a through 1.4.1.7.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qr6-r6j4-qfxh",
"modified": "2024-03-29T15:30:28Z",
"modified": "2025-04-09T18:30:40Z",
"published": "2024-03-29T15:30:28Z",
"aliases": [
"CVE-2024-30456"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.\n\n",
"details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r26g-5xh6-pgwp",
"modified": "2024-03-20T15:32:48Z",
"modified": "2025-04-09T18:30:39Z",
"published": "2024-03-20T15:32:48Z",
"aliases": [
"CVE-2024-1205"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-434"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xph7-pm58-q56v",
"modified": "2024-03-21T18:32:03Z",
"modified": "2025-04-09T18:30:39Z",
"published": "2024-03-21T18:32:03Z",
"aliases": [
"CVE-2024-2578"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through 3.5.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through 3.5.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8x5-54p6-cqvm",
"modified": "2025-02-12T21:31:54Z",
"modified": "2025-04-09T18:30:47Z",
"published": "2025-02-12T21:31:54Z",
"aliases": [
"CVE-2025-0113"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2024-0113"
},
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2025-0113"
}
],
"database_specific": {
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24q3-2w85-x8p7",
"modified": "2025-04-09T18:30:52Z",
"published": "2025-04-09T18:30:51Z",
"aliases": [
"CVE-2025-31382"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field allows Stored XSS. This issue affects Language Field: from n/a through 0.9.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31382"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/language-field/vulnerability/wordpress-language-field-plugin-0-9-csrf-to-stored-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-09T17:15:36Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24xg-93rh-whf7",
"modified": "2025-04-09T18:30:52Z",
"published": "2025-04-09T18:30:52Z",
"aliases": [
"CVE-2025-31400"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in icyleaf WS Audio Player allows Stored XSS. This issue affects WS Audio Player: from n/a through 1.1.8.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31400"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/ws-audio-player/vulnerability/wordpress-ws-audio-player-plugin-1-1-8-csrf-to-stored-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-09T17:15:38Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-299q-fv2g-6cv8",
"modified": "2025-04-09T18:30:52Z",
"published": "2025-04-09T18:30:52Z",
"aliases": [
"CVE-2025-31385"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Site Table of Contents allows Stored XSS. This issue affects Site Table of Contents: from n/a through 0.3.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31385"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/site-table-of-contents/vulnerability/wordpress-site-table-of-contents-plugin-0-3-csrf-to-stored-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-09T17:15:37Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29pc-4j9r-26vc",
"modified": "2025-04-09T18:30:51Z",
"published": "2025-04-09T18:30:51Z",
"aliases": [
"CVE-2025-31036"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in WPSolr free WPSolr allows Privilege Escalation. This issue affects WPSolr: from n/a through 24.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31036"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/wpsolr-free/vulnerability/wordpress-wpsolr-plugin-24-0-csrf-to-privilege-escalation-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-09T17:15:35Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cgp-x82p-v5h2",
"modified": "2025-04-09T18:30:53Z",
"published": "2025-04-09T18:30:53Z",
"aliases": [
"CVE-2025-32481"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in ninotheme Nino Social Connect allows Stored XSS. This issue affects Nino Social Connect: from n/a through 2.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32481"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/nino-social-connect/vulnerability/wordpress-nino-social-connect-plugin-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-09T17:15:40Z"
}
}

Some files were not shown because too many files have changed in this diff Show More