Publish Advisories

GHSA-p2w9-g2w7-8fw9
GHSA-ch7h-w2mm-gm7m
GHSA-h66w-323g-4q62
GHSA-pcw9-xw4x-jgj3
GHSA-x8qh-8j65-v4j9
GHSA-6c2p-rqx3-w4px
GHSA-4xpw-6594-8f5m
GHSA-wv7p-rjf3-9fr5
GHSA-22qr-hr3v-pmr2
GHSA-46vg-h2w6-gh78
GHSA-52xm-jh2q-v993
GHSA-cj5h-7hq4-3q37
GHSA-hqj8-x5h3-q5rg
GHSA-j2fg-56xp-h6wh
GHSA-mg9h-3wx4-hhfr
GHSA-pcp6-pxxr-g2vh
GHSA-pm77-vj97-hfv8
GHSA-pqmh-jm9r-hq9j
GHSA-prh5-fm3v-6477
GHSA-pw23-jv8r-492x
GHSA-qwgw-jf68-fjmq
GHSA-rp64-rc76-xrq5
GHSA-wc94-qmw7-2jp8
This commit is contained in:
advisory-database[bot]
2025-02-28 15:32:33 +00:00
parent abc50b36da
commit ed5723a17d
23 changed files with 578 additions and 17 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p2w9-g2w7-8fw9",
"modified": "2022-08-16T00:00:42Z",
"modified": "2025-02-28T15:30:55Z",
"published": "2022-05-24T19:03:15Z",
"aliases": [
"CVE-2021-3549"
@@ -26,6 +26,10 @@
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202208-30"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250228-0005"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ch7h-w2mm-gm7m",
"modified": "2022-09-02T00:01:10Z",
"modified": "2025-02-28T15:30:57Z",
"published": "2022-08-27T00:00:45Z",
"aliases": [
"CVE-2021-3735"
@@ -30,11 +30,16 @@
{
"type": "WEB",
"url": "https://security-tracker.debian.org/tracker/CVE-2021-3735"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250228-0009"
}
],
"database_specific": {
"cwe_ids": [
"CWE-400"
"CWE-400",
"CWE-667"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h66w-323g-4q62",
"modified": "2022-09-01T00:00:21Z",
"modified": "2025-02-28T15:30:57Z",
"published": "2022-08-26T00:03:29Z",
"aliases": [
"CVE-2021-3929"
@@ -39,9 +39,17 @@
"type": "WEB",
"url": "https://gitlab.com/qemu-project/qemu/-/issues/782"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHNN7QJCEQH7AQG5AQP2GEFAQE6K635I"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XHNN7QJCEQH7AQG5AQP2GEFAQE6K635I"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250228-0010"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcw9-xw4x-jgj3",
"modified": "2024-04-04T05:08:38Z",
"modified": "2025-02-28T15:30:58Z",
"published": "2023-06-23T21:30:33Z",
"aliases": [
"CVE-2023-34188"
@@ -34,6 +34,10 @@
{
"type": "WEB",
"url": "https://github.com/cesanta/mongoose/compare/7.9...7.10"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250228-0001"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x8qh-8j65-v4j9",
"modified": "2025-02-11T00:31:36Z",
"modified": "2025-02-28T15:30:59Z",
"published": "2024-05-14T15:32:52Z",
"aliases": [
"CVE-2024-26306"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://github.com/esnet/iperf/releases/tag/3.17"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250228-0007"
},
{
"type": "WEB",
"url": "https://www.insyde.com/security-pledge/SA-2024005"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6c2p-rqx3-w4px",
"modified": "2024-12-24T03:30:46Z",
"modified": "2025-02-28T15:30:59Z",
"published": "2024-12-23T18:30:47Z",
"aliases": [
"CVE-2024-40896"
@@ -26,6 +26,10 @@
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/761"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250228-0004"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xpw-6594-8f5m",
"modified": "2025-02-04T21:32:26Z",
"modified": "2025-02-28T15:30:59Z",
"published": "2025-01-22T15:32:34Z",
"aliases": [
"CVE-2025-0395"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0395"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250228-0006"
},
{
"type": "WEB",
"url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32582"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wv7p-rjf3-9fr5",
"modified": "2025-01-22T03:30:43Z",
"modified": "2025-02-28T15:30:59Z",
"published": "2025-01-22T03:30:43Z",
"aliases": [
"CVE-2025-23083"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://nodejs.org/en/blog/vulnerability/january-2025-security-releases"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250228-0008"
}
],
"database_specific": {
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22qr-hr3v-pmr2",
"modified": "2025-02-27T21:32:18Z",
"modified": "2025-02-28T15:31:02Z",
"published": "2025-02-27T21:32:18Z",
"aliases": [
"CVE-2024-41338"
],
"details": "A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to cause a Denial of Service (DoS) via a crafted DHCP request.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-476"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T21:15:36Z"
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46vg-h2w6-gh78",
"modified": "2025-02-28T15:31:04Z",
"published": "2025-02-28T15:31:04Z",
"aliases": [
"CVE-2025-26326"
],
"details": "A vulnerability in the remote connection complements of the NVDA (Nonvisual Desktop Access) 2024.4.1 and 2024.4.2 was identified, which allows an attacker to obtain total control of the remote system when guessing a weak password. The problem occurs because the complements accept any password typed by the user and do not have an additional authentication or checking mechanism by the computer that will be accessed. Tests indicate that over 1,000 systems use easy to guess passwords, many with less than 4 to 6 characters, including common sequences. This enables brute strength or attempt and error attacks on the part of malicious invaders. Vulnerability can be explored by a remote striker who knows or can guess the password used in the connection. As a result, the invader gets complete access to the affected system and can run commands, modify files and compromise user security.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26326"
},
{
"type": "WEB",
"url": "https://github.com/azurejoga/CVE-2025-26326"
},
{
"type": "WEB",
"url": "https://www.nvaccess.org"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T15:15:13Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52xm-jh2q-v993",
"modified": "2025-02-28T15:31:03Z",
"published": "2025-02-28T15:31:03Z",
"aliases": [
"CVE-2025-1746"
],
"details": "Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. This vulnerability could be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1746"
},
{
"type": "WEB",
"url": "https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-opencart"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T14:15:34Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cj5h-7hq4-3q37",
"modified": "2025-02-28T15:31:02Z",
"published": "2025-02-28T15:31:02Z",
"aliases": [
"CVE-2025-22271"
],
"details": "The application or its infrastructure allows for IP address spoofing by providing its own value in the \"X-Forwarded-For\" header. Thus, the action logging mechanism in the application loses accountability\n\n\nThis issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22271"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2025/02/CVE-2025-22270"
},
{
"type": "WEB",
"url": "https://cert.pl/posts/2025/02/CVE-2025-22270"
},
{
"type": "WEB",
"url": "https://docs.cyberark.com/epm/24.7.1/en/content/resources/_topnav/cc_home.htm"
}
],
"database_specific": {
"cwe_ids": [
"CWE-290"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T13:15:27Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hqj8-x5h3-q5rg",
"modified": "2025-02-28T15:31:04Z",
"published": "2025-02-28T15:31:04Z",
"aliases": [
"CVE-2025-1749"
],
"details": "HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1749"
},
{
"type": "WEB",
"url": "https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-opencart"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T14:15:35Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2fg-56xp-h6wh",
"modified": "2025-02-28T15:31:04Z",
"published": "2025-02-28T15:31:04Z",
"aliases": [
"CVE-2025-1776"
],
"details": "Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to execute arbitrary code via the query parameter in /app-google-custom-search/searchResults. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1776"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-vulnerability-soteshop"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T14:15:35Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mg9h-3wx4-hhfr",
"modified": "2025-02-28T15:31:03Z",
"published": "2025-02-28T15:31:03Z",
"aliases": [
"CVE-2025-1747"
],
"details": "HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1747"
},
{
"type": "WEB",
"url": "https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-opencart"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T14:15:35Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcp6-pxxr-g2vh",
"modified": "2025-02-28T15:31:03Z",
"published": "2025-02-28T15:31:02Z",
"aliases": [
"CVE-2025-22273"
],
"details": "Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the \"/EPMUI/VfManager.asmx/ChangePassword\" endpoint it is possible to perform a brute force attack on the current password in use.\n\n\nThis issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22273"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2025/02/CVE-2025-22270"
},
{
"type": "WEB",
"url": "https://cert.pl/posts/2025/02/CVE-2025-22270"
},
{
"type": "WEB",
"url": "https://docs.cyberark.com/epm/24.7.1/en/content/resources/_topnav/cc_home.htm"
}
],
"database_specific": {
"cwe_ids": [
"CWE-770"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T13:15:27Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pm77-vj97-hfv8",
"modified": "2025-02-28T15:31:03Z",
"published": "2025-02-28T15:31:03Z",
"aliases": [
"CVE-2025-1748"
],
"details": "HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/register.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1748"
},
{
"type": "WEB",
"url": "https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-opencart"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T14:15:35Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pqmh-jm9r-hq9j",
"modified": "2025-02-28T15:31:04Z",
"published": "2025-02-28T15:31:04Z",
"aliases": [
"CVE-2025-25916"
],
"details": "wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \\coreframe\\app\\member\\admin\\group.php.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25916"
},
{
"type": "WEB",
"url": "https://github.com/wuzhicms/wuzhicms/issues/213"
},
{
"type": "WEB",
"url": "https://gist.github.com/A7cc/e28b5790d8b40df8d418d1bd15c25d12"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T15:15:13Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-prh5-fm3v-6477",
"modified": "2025-02-27T21:32:16Z",
"modified": "2025-02-28T15:31:01Z",
"published": "2025-02-27T21:32:16Z",
"aliases": [
"CVE-2024-53408"
],
"details": "AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T20:16:01Z"
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pw23-jv8r-492x",
"modified": "2025-02-28T15:31:03Z",
"published": "2025-02-28T15:31:03Z",
"aliases": [
"CVE-2025-22272"
],
"details": "In the \"/EPMUI/ModalDlgHandler.ashx?value=showReadonlyDlg\" endpoint, it is possible to inject code in the \"modalDlgMsgInternal\" parameter via POST, which is then executed in the browser. The risk of exploiting vulnerability is reduced due to the required additional bypassing the Content-Security-Policy policy\n\n\nThis issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22272"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2025/02/CVE-2025-22270"
},
{
"type": "WEB",
"url": "https://cert.pl/posts/2025/02/CVE-2025-22270"
},
{
"type": "WEB",
"url": "https://docs.cyberark.com/epm/24.7.1/en/content/resources/_topnav/cc_home.htm"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T13:15:27Z"
}
}

Some files were not shown because too many files have changed in this diff Show More