Skip to content

Commit c2a890c

Browse files
Advisory Database Sync
1 parent dde0c82 commit c2a890c

File tree

59 files changed

+1719
-31
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

59 files changed

+1719
-31
lines changed

advisories/unreviewed/2024/10/GHSA-84mp-4xjv-gqwj/GHSA-84mp-4xjv-gqwj.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,17 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-84mp-4xjv-gqwj",
4-
"modified": "2024-10-09T18:31:43Z",
4+
"modified": "2025-12-01T18:30:23Z",
55
"published": "2024-10-09T18:31:43Z",
66
"aliases": [
77
"CVE-2024-9468"
88
],
99
"details": "A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode.",
1010
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
14+
},
1115
{
1216
"type": "CVSS_V4",
1317
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Amber"

advisories/unreviewed/2025/08/GHSA-mxg3-45rj-wpf7/GHSA-mxg3-45rj-wpf7.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-mxg3-45rj-wpf7",
4-
"modified": "2025-08-01T18:31:17Z",
4+
"modified": "2025-12-01T18:30:24Z",
55
"published": "2025-08-01T18:31:17Z",
66
"aliases": [
77
"CVE-2025-45778"
@@ -19,6 +19,10 @@
1919
"type": "ADVISORY",
2020
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45778"
2121
},
22+
{
23+
"type": "WEB",
24+
"url": "https://languagesloth.com"
25+
},
2226
{
2327
"type": "WEB",
2428
"url": "https://packetstorm.news/files/id/206262"

advisories/unreviewed/2025/08/GHSA-q29w-875r-48m6/GHSA-q29w-875r-48m6.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,8 @@
2626
],
2727
"database_specific": {
2828
"cwe_ids": [
29-
"CWE-20"
29+
"CWE-20",
30+
"CWE-22"
3031
],
3132
"severity": "MODERATE",
3233
"github_reviewed": false,

advisories/unreviewed/2025/11/GHSA-2266-54fx-rmrv/GHSA-2266-54fx-rmrv.json

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-2266-54fx-rmrv",
4-
"modified": "2025-11-21T15:31:28Z",
4+
"modified": "2025-12-01T18:30:25Z",
55
"published": "2025-11-21T15:31:28Z",
66
"aliases": [
77
"CVE-2025-66107"
88
],
99
"details": "Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -23,7 +28,7 @@
2328
"cwe_ids": [
2429
"CWE-862"
2530
],
26-
"severity": null,
31+
"severity": "MODERATE",
2732
"github_reviewed": false,
2833
"github_reviewed_at": null,
2934
"nvd_published_at": "2025-11-21T13:15:52Z"

advisories/unreviewed/2025/11/GHSA-423v-7q98-2mj3/GHSA-423v-7q98-2mj3.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,8 @@
4646
],
4747
"database_specific": {
4848
"cwe_ids": [
49-
"CWE-74"
49+
"CWE-74",
50+
"CWE-89"
5051
],
5152
"severity": "MODERATE",
5253
"github_reviewed": false,

advisories/unreviewed/2025/11/GHSA-7ppm-7xh4-78w9/GHSA-7ppm-7xh4-78w9.json

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-7ppm-7xh4-78w9",
4-
"modified": "2025-11-21T15:31:28Z",
4+
"modified": "2025-12-01T18:30:25Z",
55
"published": "2025-11-21T15:31:27Z",
66
"aliases": [
77
"CVE-2025-66108"
88
],
99
"details": "Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -23,7 +28,7 @@
2328
"cwe_ids": [
2429
"CWE-862"
2530
],
26-
"severity": null,
31+
"severity": "MODERATE",
2732
"github_reviewed": false,
2833
"github_reviewed_at": null,
2934
"nvd_published_at": "2025-11-21T13:15:52Z"

advisories/unreviewed/2025/11/GHSA-9vfr-7f57-9g97/GHSA-9vfr-7f57-9g97.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,8 @@
4646
],
4747
"database_specific": {
4848
"cwe_ids": [
49-
"CWE-74"
49+
"CWE-74",
50+
"CWE-89"
5051
],
5152
"severity": "MODERATE",
5253
"github_reviewed": false,

advisories/unreviewed/2025/11/GHSA-hvj5-hw3p-69rg/GHSA-hvj5-hw3p-69rg.json

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-hvj5-hw3p-69rg",
4-
"modified": "2025-11-21T15:31:28Z",
4+
"modified": "2025-12-01T18:30:25Z",
55
"published": "2025-11-21T15:31:27Z",
66
"aliases": [
77
"CVE-2025-66106"
88
],
99
"details": "Missing Authorization vulnerability in Essential Plugin Featured Post Creative featured-post-creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through <= 1.5.5.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -23,7 +28,7 @@
2328
"cwe_ids": [
2429
"CWE-862"
2530
],
26-
"severity": null,
31+
"severity": "MODERATE",
2732
"github_reviewed": false,
2833
"github_reviewed_at": null,
2934
"nvd_published_at": "2025-11-21T13:15:51Z"

advisories/unreviewed/2025/11/GHSA-j565-rm3x-jxcx/GHSA-j565-rm3x-jxcx.json

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,9 @@
2525
}
2626
],
2727
"database_specific": {
28-
"cwe_ids": [],
28+
"cwe_ids": [
29+
"CWE-78"
30+
],
2931
"severity": "HIGH",
3032
"github_reviewed": false,
3133
"github_reviewed_at": null,

advisories/unreviewed/2025/11/GHSA-j75f-w639-68hc/GHSA-j75f-w639-68hc.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-j75f-w639-68hc",
4-
"modified": "2025-11-10T18:30:33Z",
4+
"modified": "2025-12-01T18:30:25Z",
55
"published": "2025-11-05T17:48:28Z",
66
"aliases": [
77
"CVE-2025-63601"
@@ -27,6 +27,10 @@
2727
"type": "WEB",
2828
"url": "https://dappsec.substack.com/p/snipe-it-post-authenticated-remote"
2929
},
30+
{
31+
"type": "WEB",
32+
"url": "https://fptcloud.com/en/cve-2025-63601-proof-of-concept"
33+
},
3034
{
3135
"type": "WEB",
3236
"url": "https://github.com/grokability/snipe-it/releases/tag/v8.3.3"

0 commit comments

Comments
 (0)