Publish Advisories

GHSA-28vh-xppq-c3v4
GHSA-3phv-44jf-4v33
GHSA-5gxc-5wfv-r5f9
GHSA-8522-pjcf-fhc2
GHSA-j6m3-gc37-6r6q
GHSA-h9pr-qr4v-f87f
GHSA-qqpr-fvmc-87j3
GHSA-mww2-g4ww-rm9w
GHSA-mx84-33q7-299w
GHSA-pqhh-45r9-vjw6
GHSA-r566-fcmc-4j3v
GHSA-rm3h-m7rx-3jrq
GHSA-rpxm-rfxp-96qq
GHSA-w2x6-9r88-x4c6
GHSA-c2w9-h5r4-gc47
GHSA-frpv-8jj9-m3cv
GHSA-vxpp-6299-mxw3
GHSA-2r26-hfxw-87wc
GHSA-3cgj-v3m4-cgcq
GHSA-g8fv-r98j-937r
GHSA-g8qj-jv5h-78cp
GHSA-j238-4ph7-9jqw
This commit is contained in:
advisory-database[bot]
2025-03-14 03:32:54 +00:00
parent 97e5eb1846
commit e410ed7478
22 changed files with 274 additions and 51 deletions
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-28vh-xppq-c3v4",
"modified": "2024-03-01T15:31:38Z",
"modified": "2025-03-14T03:31:21Z",
"published": "2024-03-01T15:31:38Z",
"aliases": [
"CVE-2024-27570"
],
"details": "LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the generate_conf_router function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,11 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-01T14:15:54Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3phv-44jf-4v33",
"modified": "2024-03-18T21:31:23Z",
"modified": "2025-03-14T03:31:21Z",
"published": "2024-03-18T21:31:23Z",
"aliases": [
"CVE-2024-25654"
],
"details": "Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,11 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-276",
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-18T20:15:08Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gxc-5wfv-r5f9",
"modified": "2024-03-24T03:30:44Z",
"modified": "2025-03-14T03:31:21Z",
"published": "2024-03-24T03:30:44Z",
"aliases": [
"CVE-2024-30161"
],
"details": "In Qt before 6.5.6 and 6.6.x before 6.6.3, the wasm component may access QNetworkReply header data via a dangling pointer.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-416"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-24T01:15:45Z"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6m3-gc37-6r6q",
"modified": "2024-05-01T18:30:36Z",
"modified": "2025-03-14T03:31:21Z",
"published": "2024-03-06T00:31:27Z",
"aliases": [
"CVE-2024-24785"
],
"details": "If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -41,7 +46,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T23:15:07Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9pr-qr4v-f87f",
"modified": "2024-04-15T06:30:34Z",
"modified": "2025-03-14T03:31:21Z",
"published": "2024-04-15T06:30:34Z",
"aliases": [
"CVE-2024-1846"
],
"details": "The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-15T05:15:15Z"
@@ -41,7 +41,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-119"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mww2-g4ww-rm9w",
"modified": "2024-05-23T18:30:55Z",
"modified": "2025-03-14T03:31:22Z",
"published": "2024-05-23T18:30:55Z",
"aliases": [
"CVE-2024-2301"
],
"details": "Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management interface of the device. ",
"severity": [],
"details": "Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management interface of the device.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T17:15:28Z"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-120"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pqhh-45r9-vjw6",
"modified": "2024-05-07T21:31:45Z",
"modified": "2025-03-14T03:31:22Z",
"published": "2024-05-07T21:31:45Z",
"aliases": [
"CVE-2024-34314"
],
"details": "CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-98"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-07T19:15:08Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r566-fcmc-4j3v",
"modified": "2024-05-14T15:32:54Z",
"modified": "2025-03-14T03:31:22Z",
"published": "2024-05-14T15:32:54Z",
"aliases": [
"CVE-2024-2441"
],
"details": "The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-285"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:19:20Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rm3h-m7rx-3jrq",
"modified": "2024-05-15T06:30:44Z",
"modified": "2025-03-14T03:31:22Z",
"published": "2024-05-15T06:30:44Z",
"aliases": [
"CVE-2024-3405"
],
"details": "The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-15T06:15:09Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rpxm-rfxp-96qq",
"modified": "2024-05-01T03:30:31Z",
"modified": "2025-03-14T03:31:22Z",
"published": "2024-05-01T03:30:31Z",
"aliases": [
"CVE-2024-33767"
],
"details": "lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-01T03:15:07Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2x6-9r88-x4c6",
"modified": "2024-05-02T06:30:31Z",
"modified": "2025-03-14T03:31:22Z",
"published": "2024-05-02T06:30:31Z",
"aliases": [
"CVE-2024-3475"
],
"details": "The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:50Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2w9-h5r4-gc47",
"modified": "2024-06-20T18:34:08Z",
"modified": "2025-03-14T03:31:23Z",
"published": "2024-06-20T18:34:08Z",
"aliases": [
"CVE-2022-41324"
],
"details": "Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-20T17:15:50Z"
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1021"
"CWE-1021",
"CWE-451"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vxpp-6299-mxw3",
"modified": "2024-12-20T21:30:45Z",
"modified": "2025-03-14T03:31:23Z",
"published": "2024-06-09T21:30:34Z",
"aliases": [
"CVE-2024-4577"
@@ -91,6 +91,10 @@
"type": "WEB",
"url": "https://cert.be/en/advisory/warning-php-remote-code-execution-patch-immediately"
},
{
"type": "WEB",
"url": "https://blog.talosintelligence.com/new-persistent-attacks-japan"
},
{
"type": "WEB",
"url": "https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2r26-hfxw-87wc",
"modified": "2025-03-14T03:31:24Z",
"published": "2025-03-14T03:31:24Z",
"aliases": [
"CVE-2025-26163"
],
"details": "CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26163"
},
{
"type": "WEB",
"url": "https://github.com/Fr1t0viski/PoCs/blob/main/SQL_Injection_AutoAtendimento"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-14T03:15:44Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3cgj-v3m4-cgcq",
"modified": "2025-03-14T03:31:24Z",
"published": "2025-03-14T03:31:24Z",
"aliases": [
"CVE-2025-24855"
],
"details": "numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24855"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/libxslt/-/issues/128"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-14T02:15:15Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g8fv-r98j-937r",
"modified": "2025-03-14T03:31:24Z",
"published": "2025-03-14T03:31:24Z",
"aliases": [
"CVE-2024-55549"
],
"details": "xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55549"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/libxslt/-/issues/127"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-14T02:15:15Z"
}
}

Some files were not shown because too many files have changed in this diff Show More