Publish Advisories

GHSA-54qp-w9cp-g8g3
GHSA-65wf-c9wx-f4v7
GHSA-7wfq-7p2f-6344
GHSA-9589-mpwg-8xq6
GHSA-99xf-gcww-2c64
GHSA-9qwg-ch53-9rxw
GHSA-f4vp-qjpg-x8wq
GHSA-fp4x-j6ch-w8q5
GHSA-wcmh-fj7m-gv6r
GHSA-78jm-3rg9-qvxq
GHSA-9c2j-cwmf-39vw
GHSA-cvpp-rmjx-5x2m
GHSA-gq3q-6947-35qj
GHSA-p2qp-gwg4-3p43
GHSA-qhm6-4q4w-cv6h
GHSA-v7hj-8fmw-5mw6
This commit is contained in:
advisory-database[bot]
2025-05-29 09:32:38 +00:00
parent b3a5883ccf
commit f6eac15575
16 changed files with 246 additions and 12 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-54qp-w9cp-g8g3",
"modified": "2025-05-13T21:30:31Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-04-03T15:31:19Z",
"aliases": [
"CVE-2025-32053"
@@ -39,6 +39,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:7436"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8292"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-32053"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-65wf-c9wx-f4v7",
"modified": "2025-04-14T15:31:59Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-04-14T15:31:59Z",
"aliases": [
"CVE-2025-32910"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32910"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8292"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-32910"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7wfq-7p2f-6344",
"modified": "2025-05-26T12:30:29Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-04-14T15:31:58Z",
"aliases": [
"CVE-2025-32907"
@@ -39,6 +39,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8128"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8292"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-32907"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9589-mpwg-8xq6",
"modified": "2025-05-13T15:32:11Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-04-14T15:31:58Z",
"aliases": [
"CVE-2025-32913"
@@ -55,6 +55,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:7436"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8292"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-32913"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99xf-gcww-2c64",
"modified": "2025-05-13T21:30:31Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-04-03T15:31:19Z",
"aliases": [
"CVE-2025-32050"
@@ -39,6 +39,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:7436"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8292"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-32050"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qwg-ch53-9rxw",
"modified": "2025-05-13T21:30:31Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-04-03T15:31:19Z",
"aliases": [
"CVE-2025-32052"
@@ -39,6 +39,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:7436"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8292"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-32052"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f4vp-qjpg-x8wq",
"modified": "2025-05-13T21:30:31Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-04-14T15:31:58Z",
"aliases": [
"CVE-2025-32906"
@@ -59,6 +59,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:7505"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8292"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-32906"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fp4x-j6ch-w8q5",
"modified": "2025-05-13T15:32:11Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-04-15T18:31:45Z",
"aliases": [
"CVE-2025-32911"
@@ -55,6 +55,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:7436"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8292"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-32911"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wcmh-fj7m-gv6r",
"modified": "2025-04-14T15:31:59Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-04-14T15:31:59Z",
"aliases": [
"CVE-2025-32909"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32909"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:8292"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-32909"
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78jm-3rg9-qvxq",
"modified": "2025-05-29T09:31:00Z",
"published": "2025-05-29T09:31:00Z",
"aliases": [
"CVE-2025-4687"
],
"details": "In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and registers to the platform directly, they are added to the attackers company without their knowledge. The victims account and their company can then be managed by the attacker.This issue affects RMS: before 5.7.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4687"
},
{
"type": "WEB",
"url": "https://jowin922.medium.com/cve-2025-4687-pre-account-takeover-through-invite-on-teletonika-rms-website-972335378829"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-29T09:15:27Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c2j-cwmf-39vw",
"modified": "2025-05-29T09:31:00Z",
"published": "2025-05-29T09:31:00Z",
"aliases": [
"CVE-2025-4670"
],
"details": "The Easy Digital Downloads eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4670"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3301852"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/easy-digital-downloads/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/95c5bfc5-53b3-482f-856b-db6b6cac93a2?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-29T09:15:27Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvpp-rmjx-5x2m",
"modified": "2025-05-15T21:31:26Z",
"modified": "2025-05-29T09:30:59Z",
"published": "2025-05-14T00:32:21Z",
"aliases": [
"CVE-2025-47905"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47905"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00040.html"
},
{
"type": "WEB",
"url": "https://varnish-cache.org/security/VSV00016.html"
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gq3q-6947-35qj",
"modified": "2025-05-29T09:31:00Z",
"published": "2025-05-29T09:31:00Z",
"aliases": [
"CVE-2025-5122"
],
"details": "The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5122"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/map-block-leaflet/trunk/build/leaflet-map-block/render.php#L41"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3302407"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/map-block-leaflet/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/372f1cf3-df33-444c-b31e-8f71d128e30b?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-29T09:15:27Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p2qp-gwg4-3p43",
"modified": "2025-05-25T09:33:47Z",
"modified": "2025-05-29T09:31:00Z",
"published": "2025-05-25T09:33:47Z",
"aliases": [
"CVE-2025-5146"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://anonymous.4open.science/r/netcore_command_injection2-4583F2DA"
},
{
"type": "WEB",
"url": "https://github.com/Exploo0Osion/netcore_command_injection_2"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310234"
@@ -0,0 +1,60 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qhm6-4q4w-cv6h",
"modified": "2025-05-29T09:31:00Z",
"published": "2025-05-29T09:31:00Z",
"aliases": [
"CVE-2025-5286"
],
"details": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the additional_settings parameter in all versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5286"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/bold-page-builder/tags/5.3.6/content_elements/bt_bb_content_slider/bt_bb_content_slider.php#L156"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/bold-page-builder/tags/5.3.6/content_elements/bt_bb_content_slider/bt_bb_content_slider.php#L176"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/bold-page-builder/tags/5.3.6/content_elements/bt_bb_content_slider/bt_bb_content_slider.php#L7"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/bold-page-builder/tags/5.3.7/content_elements/bt_bb_content_slider/bt_bb_content_slider.php#L156"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3302452"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/bold-page-builder/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9ae076e4-ad15-4069-be10-f0f4aced4132?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-29T09:15:28Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7hj-8fmw-5mw6",
"modified": "2025-05-25T12:30:24Z",
"modified": "2025-05-29T09:31:00Z",
"published": "2025-05-25T12:30:24Z",
"aliases": [
"CVE-2025-5147"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://anonymous.4open.science/r/netcore_command_injection3-54DFaW2G"
},
{
"type": "WEB",
"url": "https://github.com/Exploo0Osion/netcore_command_injection_3"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310235"