diff --git a/data/anchore/2024/CVE-2024-11582.json b/data/anchore/2024/CVE-2024-11582.json new file mode 100644 index 00000000..24ecc022 --- /dev/null +++ b/data/anchore/2024/CVE-2024-11582.json @@ -0,0 +1,45 @@ +{ + "additionalMetadata": { + "cna": "wordfence", + "cveId": "CVE-2024-11582", + "description": "The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://plugins.trac.wordpress.org/browser/subscribe2/tags/10.43/classes/class-s2-list-table.php#L72", + "https://www.wordfence.com/threat-intel/vulnerabilities/id/36777e39-be45-41f2-beca-2971e15b77cd?source=cve" + ], + "upstream": { + "datePublished": "2025-02-19T03:21:11.532Z", + "dateReserved": "2024-11-20T22:09:14.355Z", + "dateUpdated": "2025-02-19T14:58:22.696Z", + "digest": "87d2ab853d85fb2877293a37e03458857b2ddcdcd210c6acf02a6196348cd111" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://wordpress.org/plugins", + "cpes": [ + "cpe:2.3:a:subscribe2_project:subscribe2:*:*:*:*:*:wordpress:*:*" + ], + "packageName": "subscribe2", + "packageType": "wordpress-plugin", + "product": "Subscribe2 – Form, Email Subscribers & Newsletters", + "repo": "https://plugins.svn.wordpress.org/subscribe2", + "vendor": "wedevs", + "versions": [ + { + "lessThan": "10.44", + "status": "affected", + "version": "0", + "versionType": "semver" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2024/CVE-2024-13405.json b/data/anchore/2024/CVE-2024-13405.json new file mode 100644 index 00000000..76d24b33 --- /dev/null +++ b/data/anchore/2024/CVE-2024-13405.json @@ -0,0 +1,45 @@ +{ + "additionalMetadata": { + "cna": "wordfence", + "cveId": "CVE-2024-13405", + "description": "The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation on the 'awp_ip_deny' page. This makes it possible for unauthenticated attackers to block IP addresses via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://wordpress.org/plugins/apptivo-business-site/", + "https://www.wordfence.com/threat-intel/vulnerabilities/id/f8225e3c-5413-4406-a31b-80829b6b330a?source=cve" + ], + "upstream": { + "datePublished": "2025-02-19T07:32:15.148Z", + "dateReserved": "2025-01-15T16:46:14.750Z", + "dateUpdated": "2025-02-19T15:08:08.123Z", + "digest": "75a05ca4f0941bec3bd0be0a803dc7703519e5d50a9858af997dca938d821f4e" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://wordpress.org/plugins", + "cpes": [ + "cpe:2.3:a:apptivo:apptivo_business_site_crm:*:*:*:*:*:wordpress:*:*" + ], + "packageName": "apptivo-business-site", + "packageType": "wordpress-plugin", + "product": "Apptivo Business Site CRM", + "repo": "https://plugins.svn.wordpress.org/apptivo-business-site", + "vendor": "apptivo", + "versions": [ + { + "lessThanOrEqual": "5.3", + "status": "affected", + "version": "0", + "versionType": "semver" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2024/CVE-2024-13740.json b/data/anchore/2024/CVE-2024-13740.json index c483382c..26588c5d 100644 --- a/data/anchore/2024/CVE-2024-13740.json +++ b/data/anchore/2024/CVE-2024-13740.json @@ -22,7 +22,7 @@ "cpes": [ "cpe:2.3:a:metagauss:profilegrid:*:*:*:*:*:wordpress:*:*" ], - "packageName": "profilegrid", + "packageName": "profilegrid-user-profiles-groups-and-communities", "packageType": "wordpress-plugin", "product": "ProfileGrid – User Profiles, Groups and Communities", "repo": "https://plugins.svn.wordpress.org/profilegrid", diff --git a/data/anchore/2024/CVE-2024-13741.json b/data/anchore/2024/CVE-2024-13741.json index 9163095e..a914625a 100644 --- a/data/anchore/2024/CVE-2024-13741.json +++ b/data/anchore/2024/CVE-2024-13741.json @@ -23,7 +23,7 @@ "cpes": [ "cpe:2.3:a:metagauss:profilegrid:*:*:*:*:*:wordpress:*:*" ], - "packageName": "profilegrid", + "packageName": "profilegrid-user-profiles-groups-and-communities", "packageType": "wordpress-plugin", "product": "ProfileGrid – User Profiles, Groups and Communities", "repo": "https://plugins.svn.wordpress.org/profilegrid", diff --git a/data/anchore/2024/CVE-2024-13783.json b/data/anchore/2024/CVE-2024-13783.json index 2e1fe533..96cc034d 100644 --- a/data/anchore/2024/CVE-2024-13783.json +++ b/data/anchore/2024/CVE-2024-13783.json @@ -25,7 +25,7 @@ "cpe:2.3:a:ncrafts:formcraft:*:*:*:*:*:wordpress:*:*", "cpe:2.3:a:subtlewebinc:formcraft3:*:*:*:*:*:wordpress:*:*" ], - "packageName": "formcraft-form-builder", + "packageName": "formcraft3", "packageType": "wordpress-plugin", "product": "FormCraft", "repo": "https://plugins.svn.wordpress.org/formcraft-form-builder", diff --git a/data/anchore/2024/CVE-2024-43957.json b/data/anchore/2024/CVE-2024-43957.json index 1dda8437..964bc857 100644 --- a/data/anchore/2024/CVE-2024-43957.json +++ b/data/anchore/2024/CVE-2024-43957.json @@ -22,7 +22,7 @@ "vendor": "Sk. Abul Hasan", "versions": [ { - "lessThanOrEqual": "1.9", + "lessThan": "2.2", "status": "affected", "version": "0", "versionType": "custom" diff --git a/data/anchore/2025/CVE-2025-0817.json b/data/anchore/2025/CVE-2025-0817.json index e49ae4ab..bbfa8ee8 100644 --- a/data/anchore/2025/CVE-2025-0817.json +++ b/data/anchore/2025/CVE-2025-0817.json @@ -25,7 +25,7 @@ "cpe:2.3:a:ncrafts:formcraft:*:*:*:*:*:wordpress:*:*", "cpe:2.3:a:subtlewebinc:formcraft3:*:*:*:*:*:wordpress:*:*" ], - "packageName": "formcraft-form-builder", + "packageName": "formcraft3", "packageType": "wordpress-plugin", "product": "FormCraft", "repo": "https://plugins.svn.wordpress.org/formcraft-form-builder", diff --git a/data/anchore/2025/CVE-2025-0968.json b/data/anchore/2025/CVE-2025-0968.json new file mode 100644 index 00000000..a54f57ae --- /dev/null +++ b/data/anchore/2025/CVE-2025-0968.json @@ -0,0 +1,47 @@ +{ + "additionalMetadata": { + "cna": "wordfence", + "cveId": "CVE-2025-0968", + "description": "The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, trashed and private items.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://plugins.trac.wordpress.org/browser/elementskit-lite/trunk/modules/megamenu/api.php#L47", + "https://plugins.trac.wordpress.org/changeset/3237243/", + "https://wordpress.org/plugins/elementskit-lite/#developers", + "https://www.wordfence.com/threat-intel/vulnerabilities/id/432ac3b1-8f1d-442f-8e8d-62a1f26ba259?source=cve" + ], + "upstream": { + "datePublished": "2025-02-19T11:10:39.448Z", + "dateReserved": "2025-02-01T21:47:17.502Z", + "dateUpdated": "2025-02-19T14:37:10.760Z", + "digest": "223ea859299f2a7befb06d67cced8328ec2881ea8df196a630ab1603ffab2c69" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://wordpress.org/plugins", + "cpes": [ + "cpe:2.3:a:wpmet:elements_kit_elementor_addons:*:*:*:*:*:wordpress:*:*" + ], + "packageName": "elementskit-lite", + "packageType": "wordpress-plugin", + "product": "ElementsKit Elementor addons", + "repo": "https://plugins.svn.wordpress.org/elementskit-lite", + "vendor": "xpeedstudio", + "versions": [ + { + "lessThan": "3.4.1", + "status": "affected", + "version": "0", + "versionType": "semver" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-0999.json b/data/anchore/2025/CVE-2025-0999.json new file mode 100644 index 00000000..440e08a2 --- /dev/null +++ b/data/anchore/2025/CVE-2025-0999.json @@ -0,0 +1,41 @@ +{ + "additionalMetadata": { + "cna": "chrome", + "cveId": "CVE-2025-0999", + "description": "Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_18.html", + "https://issues.chromium.org/issues/394350433" + ], + "upstream": { + "datePublished": "2025-02-19T16:55:30.675Z", + "dateReserved": "2025-02-03T18:04:39.217Z", + "dateUpdated": "2025-02-19T20:08:12.953Z", + "digest": "df0de1d83073ed8cdd3d4011a4583dcc158d7b1835f96171d4e85a70a45b9290" + } + }, + "adp": { + "affected": [ + { + "cpes": [ + "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*" + ], + "product": "Chrome", + "vendor": "Google", + "versions": [ + { + "lessThan": "133.0.6943.126", + "status": "affected", + "version": "0", + "versionType": "custom" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-1006.json b/data/anchore/2025/CVE-2025-1006.json new file mode 100644 index 00000000..e7ba05a5 --- /dev/null +++ b/data/anchore/2025/CVE-2025-1006.json @@ -0,0 +1,41 @@ +{ + "additionalMetadata": { + "cna": "chrome", + "cveId": "CVE-2025-1006", + "description": "Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. (Chromium security severity: Medium)", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_18.html", + "https://issues.chromium.org/issues/390590778" + ], + "upstream": { + "datePublished": "2025-02-19T16:55:31.747Z", + "dateReserved": "2025-02-03T21:24:57.862Z", + "dateUpdated": "2025-02-19T20:09:48.316Z", + "digest": "df0de1d83073ed8cdd3d4011a4583dcc158d7b1835f96171d4e85a70a45b9290" + } + }, + "adp": { + "affected": [ + { + "cpes": [ + "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*" + ], + "product": "Chrome", + "vendor": "Google", + "versions": [ + { + "lessThan": "133.0.6943.126", + "status": "affected", + "version": "0", + "versionType": "custom" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-1065.json b/data/anchore/2025/CVE-2025-1065.json new file mode 100644 index 00000000..071cc02f --- /dev/null +++ b/data/anchore/2025/CVE-2025-1065.json @@ -0,0 +1,45 @@ +{ + "additionalMetadata": { + "cna": "wordfence", + "cveId": "CVE-2025-1065", + "description": "The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://plugins.trac.wordpress.org/changeset/3240066/visualizer", + "https://www.wordfence.com/threat-intel/vulnerabilities/id/17c1de7b-5178-4fbe-a515-169de4323ae7?source=cve" + ], + "upstream": { + "datePublished": "2025-02-19T05:22:52.516Z", + "dateReserved": "2025-02-05T18:14:04.973Z", + "dateUpdated": "2025-02-19T14:56:01.047Z", + "digest": "bb777eff2c3507e04604480436eddc038108f96d5db5a2f99fc85815ee3b4cf7" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://wordpress.org/plugins", + "cpes": [ + "cpe:2.3:a:themeisle:visualizer:*:*:*:*:*:wordpress:*:*" + ], + "packageName": "visualizer", + "packageType": "wordpress-plugin", + "product": "Visualizer: Tables and Charts Manager for WordPress", + "repo": "https://plugins.svn.wordpress.org/visualizer", + "vendor": "themeisle", + "versions": [ + { + "lessThan": "3.11.9", + "status": "affected", + "version": "0", + "versionType": "semver" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-1426.json b/data/anchore/2025/CVE-2025-1426.json new file mode 100644 index 00000000..8c6a2c8a --- /dev/null +++ b/data/anchore/2025/CVE-2025-1426.json @@ -0,0 +1,41 @@ +{ + "additionalMetadata": { + "cna": "chrome", + "cveId": "CVE-2025-1426", + "description": "Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_18.html", + "https://issues.chromium.org/issues/383465163" + ], + "upstream": { + "datePublished": "2025-02-19T16:55:31.252Z", + "dateReserved": "2025-02-18T14:20:02.551Z", + "dateUpdated": "2025-02-19T20:09:06.807Z", + "digest": "df0de1d83073ed8cdd3d4011a4583dcc158d7b1835f96171d4e85a70a45b9290" + } + }, + "adp": { + "affected": [ + { + "cpes": [ + "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*" + ], + "product": "Chrome", + "vendor": "Google", + "versions": [ + { + "lessThan": "133.0.6943.126", + "status": "affected", + "version": "0", + "versionType": "custom" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-1441.json b/data/anchore/2025/CVE-2025-1441.json new file mode 100644 index 00000000..ba456d4d --- /dev/null +++ b/data/anchore/2025/CVE-2025-1441.json @@ -0,0 +1,46 @@ +{ + "additionalMetadata": { + "cna": "wordfence", + "cveId": "CVE-2025-1441", + "description": "The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1007/classes/modules/wpr-filter-woo-products.php#L1895", + "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1008/classes/modules/wpr-filter-woo-products.php#L1904", + "https://www.wordfence.com/threat-intel/vulnerabilities/id/6bc6a436-6df3-4eaf-a16b-d8b3c3ca7d87?source=cve" + ], + "upstream": { + "datePublished": "2025-02-19T04:21:28.536Z", + "dateReserved": "2025-02-18T15:29:36.812Z", + "dateUpdated": "2025-02-19T14:57:36.571Z", + "digest": "4f8cb51d5e622cc87c73cb368e75a58742bc2072c6142deff3aaf3b8b815b3c3" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://wordpress.org/plugins", + "cpes": [ + "cpe:2.3:a:royal-elementor-addons:royal_elementor_addons:*:*:*:*:*:wordpress:*:*" + ], + "packageName": "royal-elementor-addons", + "packageType": "wordpress-plugin", + "product": "Royal Elementor Addons and Templates", + "repo": "https://plugins.svn.wordpress.org/royal-elementor-addons", + "vendor": "wproyal", + "versions": [ + { + "lessThan": "1.7.1008", + "status": "affected", + "version": "0", + "versionType": "semver" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-22661.json b/data/anchore/2025/CVE-2025-22661.json index d8297038..e785caf2 100644 --- a/data/anchore/2025/CVE-2025-22661.json +++ b/data/anchore/2025/CVE-2025-22661.json @@ -28,7 +28,7 @@ "vendor": "vcita.com", "versions": [ { - "lessThanOrEqual": "3.20.0", + "lessThan": "3.30.0", "status": "affected", "version": "0", "versionType": "custom" diff --git a/data/anchore/2025/CVE-2025-24533.json b/data/anchore/2025/CVE-2025-24533.json index 9f672e75..061ddbd5 100644 --- a/data/anchore/2025/CVE-2025-24533.json +++ b/data/anchore/2025/CVE-2025-24533.json @@ -31,7 +31,7 @@ "vendor": "MetaSlider", "versions": [ { - "lessThanOrEqual": "3.92.0", + "lessThan": "3.92.1", "status": "affected", "version": "0", "versionType": "custom" @@ -42,6 +42,11 @@ "providerMetadata": { "orgId": "00000000-0000-4000-8000-000000000000", "shortName": "anchoreadp" - } + }, + "references": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/50f0f0d9-973d-4903-84aa-a1a68a5c19e2?source=cve" + } + ] } } \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-24537.json b/data/anchore/2025/CVE-2025-24537.json index 244b75e2..dfe7334a 100644 --- a/data/anchore/2025/CVE-2025-24537.json +++ b/data/anchore/2025/CVE-2025-24537.json @@ -33,7 +33,7 @@ "vendor": "The Events Calendar", "versions": [ { - "lessThanOrEqual": "6.7.0", + "lessThan": "6.7.1", "status": "affected", "version": "0", "versionType": "custom" @@ -44,6 +44,11 @@ "providerMetadata": { "orgId": "00000000-0000-4000-8000-000000000000", "shortName": "anchoreadp" - } + }, + "references": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dc6a1a39-509a-4c82-8111-f05573d0f88b?source=cve" + } + ] } } \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-24540.json b/data/anchore/2025/CVE-2025-24540.json index d5a1ddf0..69b0b9e4 100644 --- a/data/anchore/2025/CVE-2025-24540.json +++ b/data/anchore/2025/CVE-2025-24540.json @@ -32,7 +32,7 @@ "vendor": "SeedProd", "versions": [ { - "lessThanOrEqual": "6.18.9", + "lessThan": "6.18.10", "status": "affected", "version": "0", "versionType": "custom" @@ -43,6 +43,11 @@ "providerMetadata": { "orgId": "00000000-0000-4000-8000-000000000000", "shortName": "anchoreadp" - } + }, + "references": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4fe784a0-d466-4124-b712-18c19f9de53a?source=cve" + } + ] } } \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-24584.json b/data/anchore/2025/CVE-2025-24584.json index abce2c26..8820a36d 100644 --- a/data/anchore/2025/CVE-2025-24584.json +++ b/data/anchore/2025/CVE-2025-24584.json @@ -31,7 +31,7 @@ "vendor": "BdThemes", "versions": [ { - "lessThanOrEqual": "2.3.0", + "lessThan": "2.3.1", "status": "affected", "version": "0", "versionType": "custom" @@ -42,6 +42,11 @@ "providerMetadata": { "orgId": "00000000-0000-4000-8000-000000000000", "shortName": "anchoreadp" - } + }, + "references": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7c5ba00f-f5ec-42d9-8f30-9ce30a94fb0d?source=cve" + } + ] } } \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-24606.json b/data/anchore/2025/CVE-2025-24606.json index ff21b652..a22569a5 100644 --- a/data/anchore/2025/CVE-2025-24606.json +++ b/data/anchore/2025/CVE-2025-24606.json @@ -31,7 +31,7 @@ "vendor": "Sprout Invoices", "versions": [ { - "lessThanOrEqual": "20.8.1", + "lessThan": "20.8.2", "status": "affected", "version": "0", "versionType": "custom" @@ -42,6 +42,11 @@ "providerMetadata": { "orgId": "00000000-0000-4000-8000-000000000000", "shortName": "anchoreadp" - } + }, + "references": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/42106dad-c568-4a79-af56-2d714dd8f487?source=cve" + } + ] } } \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-24632.json b/data/anchore/2025/CVE-2025-24632.json index 9db85607..4d77a6e8 100644 --- a/data/anchore/2025/CVE-2025-24632.json +++ b/data/anchore/2025/CVE-2025-24632.json @@ -31,7 +31,7 @@ "vendor": "AlgolPlus", "versions": [ { - "lessThanOrEqual": "4.9.0", + "lessThan": "4.9.1", "status": "affected", "version": "0", "versionType": "custom" @@ -42,6 +42,11 @@ "providerMetadata": { "orgId": "00000000-0000-4000-8000-000000000000", "shortName": "anchoreadp" - } + }, + "references": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/88b40b01-2e4c-4368-960a-ffc8f0978e59?source=cve" + } + ] } } \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-24635.json b/data/anchore/2025/CVE-2025-24635.json index bb4a1ad4..ae36b9e9 100644 --- a/data/anchore/2025/CVE-2025-24635.json +++ b/data/anchore/2025/CVE-2025-24635.json @@ -31,7 +31,7 @@ "vendor": "Paytm", "versions": [ { - "lessThanOrEqual": "2.3.1", + "lessThan": "2.3.2", "status": "affected", "version": "0", "versionType": "custom" @@ -42,6 +42,11 @@ "providerMetadata": { "orgId": "00000000-0000-4000-8000-000000000000", "shortName": "anchoreadp" - } + }, + "references": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8759bb88-2c19-4875-99c1-f83a2abaffa2?source=cve" + } + ] } } \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-24680.json b/data/anchore/2025/CVE-2025-24680.json index bcc5ab88..7536d18c 100644 --- a/data/anchore/2025/CVE-2025-24680.json +++ b/data/anchore/2025/CVE-2025-24680.json @@ -31,7 +31,7 @@ "vendor": "WpMultiStoreLocator", "versions": [ { - "lessThanOrEqual": "2.4.7", + "lessThan": "2.5.1", "status": "affected", "version": "0", "versionType": "custom" @@ -42,6 +42,11 @@ "providerMetadata": { "orgId": "00000000-0000-4000-8000-000000000000", "shortName": "anchoreadp" - } + }, + "references": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/74ec7886-153a-44f2-9603-d4f1780132ad?source=cve" + } + ] } } \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-24806.json b/data/anchore/2025/CVE-2025-24806.json new file mode 100644 index 00000000..e58064e4 --- /dev/null +++ b/data/anchore/2025/CVE-2025-24806.json @@ -0,0 +1,45 @@ +{ + "additionalMetadata": { + "cna": "github_m", + "cveId": "CVE-2025-24806", + "description": "Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. If users are allowed to sign in via both username and email the regulation system treats these as separate login events. This leads to the regulation limitations being effectively doubled assuming an attacker using brute-force to find a user password. It's important to note that due to the effective operation of regulation where no user-facing sign of their regulation ban being visible either via timing or via API responses, it's effectively impossible to determine if a failure occurs due to a bad username password combination, or a effective ban blocking the attempt which heavily mitigates any form of brute-force. This occurs because the records and counting process for this system uses the method utilized for sign in rather than the effective username attribute. This has a minimal impact on account security, this impact is increased naturally in scenarios when there is no two-factor authentication required and weak passwords are used. This makes it a bit easier to brute-force a password. A patch for this issue has been applied to versions 4.38.19, and 4.39.0. Users are advised to upgrade. Users unable to upgrade should 1. Not heavily modify the default settings in a way that ends up with shorter or less frequent regulation bans. The default settings effectively mitigate any potential for this issue to be exploited. and 2. Disable the ability for users to login via an email address.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://github.com/authelia/authelia/commit/d4a54189aa6563912f9427b96dcb01eacafa785c", + "https://github.com/authelia/authelia/security/advisories/GHSA-m5mf-3963-4x26" + ], + "upstream": { + "datePublished": "2025-02-19T17:19:30.909Z", + "dateReserved": "2025-01-23T17:11:35.840Z", + "dateUpdated": "2025-02-19T18:39:15.855Z", + "digest": "5b3a70ebf4ee4e7b5a4a82b173506a6dba5dab4d6b23e161f21023a3609e5209" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://pkg.go.dev", + "cpes": [ + "cpe:2.3:a:authelia:authelia:*:*:*:*:*:go:*:*" + ], + "packageName": "github.com/authelia/authelia", + "packageType": "go-module", + "product": "authelia", + "repo": "https://github.com/authelia/authelia", + "vendor": "authelia", + "versions": [ + { + "lessThan": "4.38.19", + "status": "affected", + "version": "0", + "versionType": "custom" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-24965.json b/data/anchore/2025/CVE-2025-24965.json new file mode 100644 index 00000000..f212f1cf --- /dev/null +++ b/data/anchore/2025/CVE-2025-24965.json @@ -0,0 +1,45 @@ +{ + "additionalMetadata": { + "cna": "github_m", + "cveId": "CVE-2025-24965", + "description": "crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host. No special permissions are needed, only the ability for the current user to write to the target file. The problem is fixed in crun 1.20 and all users are advised to upgrade. There are no known workarounds for this vulnerability.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://github.com/containers/crun/commit/0aec82c2b686f0b1793deed43b46524fe2e8b5a7", + "https://github.com/containers/crun/releases/tag/1.20", + "https://github.com/containers/crun/security/advisories/GHSA-f42g-r5jj-qh4j" + ], + "upstream": { + "datePublished": "2025-02-19T16:46:31.602Z", + "dateReserved": "2025-01-29T15:18:03.209Z", + "dateUpdated": "2025-02-19T16:56:05.966Z", + "digest": "4f285b9d1c3a0eac0f59624500c280c57de58d9faaf8c91b5bf38c5de4da3df2" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://github.com", + "cpes": [ + "cpe:2.3:a:crun_project:crun:*:*:*:*:*:*:*:*" + ], + "packageName": "containers/crun", + "product": "crun", + "repo": "https://github.com/containers/crun", + "vendor": "containers", + "versions": [ + { + "lessThan": "1.20", + "status": "affected", + "version": "0", + "versionType": "custom" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-25196.json b/data/anchore/2025/CVE-2025-25196.json new file mode 100644 index 00000000..1127ab63 --- /dev/null +++ b/data/anchore/2025/CVE-2025-25196.json @@ -0,0 +1,45 @@ +{ + "additionalMetadata": { + "cna": "github_m", + "cveId": "CVE-2025-25196", + "description": "OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users on OpenFGA v1.8.4 or previous, specifically under the following conditions are affected by this authorization bypass vulnerability: 1. Calling Check API or ListObjects with a model that has a relation directly assignable to both public access AND userset with the same type. 2. A type bound public access tuple is assigned to an object. 3. userset tuple is not assigned to the same object. and 4. Check request's user field is a userset that has the same type as the type bound public access tuple's user type. Users are advised to upgrade to v1.8.5 which is backwards compatible. There are no known workarounds for this vulnerability.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://github.com/openfga/openfga/commit/0aee4f47e0c642de78831ceb27bb62b116f49588", + "https://github.com/openfga/openfga/security/advisories/GHSA-g4v5-6f5p-m38j" + ], + "upstream": { + "datePublished": "2025-02-19T20:18:30.309Z", + "dateReserved": "2025-02-03T19:30:53.400Z", + "dateUpdated": "2025-02-19T20:43:08.660Z", + "digest": "693b6fdd94494656d5e10392b4535fecb7fda379b62ff875ec8ad73cfb4522ab" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://pkg.go.dev", + "cpes": [ + "cpe:2.3:a:openfga:openfga:*:*:*:*:*:go:*:*" + ], + "packageName": "github.com/openfga/openfga", + "packageType": "go-module", + "product": "openfga", + "repo": "https://github.com/openfga/openfga", + "vendor": "openfga", + "versions": [ + { + "lessThan": "1.8.5", + "status": "affected", + "version": "0", + "versionType": "custom" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-27089.json b/data/anchore/2025/CVE-2025-27089.json new file mode 100644 index 00000000..13979863 --- /dev/null +++ b/data/anchore/2025/CVE-2025-27089.json @@ -0,0 +1,46 @@ +{ + "additionalMetadata": { + "cna": "github_m", + "cveId": "CVE-2025-27089", + "description": "Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two overlapping policies for the `update` action that allow access to different fields, instead of correctly checking access permissions against the item they apply for the user is allowed to update the superset of fields allowed by any of the policies. E.g. have one policy allowing update access to `field_a` if the `id == 1` and one policy allowing update access to `field_b` if the `id == 2`. The user with both these policies is allowed to update both `field_a` and `field_b` for the items with ids `1` and `2`. Before v11, if a user was allowed to update an item they were allowed to update the fields that the single permission, that applied to that item, listed. With overlapping permissions this isn't as clear cut anymore and the union of fields might not be the fields the user is allowed to update for that specific item. The solution that this PR introduces is to evaluate the permissions for each field that the user tries to update in the validateItemAccess DB query, instead of only verifying access to the item as a whole. This is done by, instead of returning the actual field value, returning a flag that indicates if the user has access to that field. This uses the same case/when mechanism that is used for stripping out non permitted field that is at the core of the permissions engine. As a result, for every item that the access is validated for, the expected result is an item that has either 1 or null for all the \"requested\" fields instead of any of the actual field values. These results are not useful for anything other than verifying the field level access permissions. The final check in validateItemAccess can either fail if the number of items does not match the number of items the access is checked for (ie. the user does not have access to the item at all) or if not all of the passed in fields have access permissions for any of the returned items. This is a vulnerability that allows update access to unintended fields, potentially impacting the password field for user accounts. This has been addressed in version 11.1.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://github.com/directus/directus/releases/tag/v11.1.2", + "https://github.com/directus/directus/security/advisories/GHSA-99vm-5v2h-h6r6" + ], + "upstream": { + "datePublished": "2025-02-19T16:42:48.233Z", + "dateReserved": "2025-02-18T16:44:48.763Z", + "dateUpdated": "2025-02-19T17:19:06.240Z", + "digest": "60f6e1a14d8410a895b1e5be1d647f27beb38cc1c58644a49dcbcb57d436ab86" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://registry.npmjs.org", + "cpes": [ + "cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*", + "cpe:2.3:a:rangerstudio:directus:*:*:*:*:*:node.js:*:*" + ], + "packageName": "directus", + "packageType": "npm", + "product": "directus", + "repo": "https://github.com/directus/directus", + "vendor": "directus", + "versions": [ + { + "lessThan": "11.1.2", + "status": "affected", + "version": "11.0.0", + "versionType": "custom" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2025/CVE-2025-27090.json b/data/anchore/2025/CVE-2025-27090.json new file mode 100644 index 00000000..8bbc008d --- /dev/null +++ b/data/anchore/2025/CVE-2025-27090.json @@ -0,0 +1,46 @@ +{ + "additionalMetadata": { + "cna": "github_m", + "cveId": "CVE-2025-27090", + "description": "Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed the implant to do so. The only impact that has been shown is the exposure of the server's IP address to a third party. This issue has been addressed in version 1.5.43 and all users are advised to upgrade. There are no known workarounds for this vulnerability.", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://github.com/BishopFox/sliver/commit/0f340a25cf3d496ed870dae7da39eab4427bc16f", + "https://github.com/BishopFox/sliver/commit/10e245326070c6a5884a02e0790bb7e2baefb3a1", + "https://github.com/BishopFox/sliver/security/advisories/GHSA-fh4v-v779-4g2w" + ], + "upstream": { + "datePublished": "2025-02-19T21:11:06.671Z", + "dateReserved": "2025-02-18T16:44:48.764Z", + "dateUpdated": "2025-02-19T21:37:35.320Z", + "digest": "846196f492c5dd6fe3d6750056ddc54d6e130c1bf3c0f89c12560d9d3885afb2" + } + }, + "adp": { + "affected": [ + { + "collectionURL": "https://pkg.go.dev", + "cpes": [ + "cpe:2.3:a:bishopfox:sliver:*:*:*:*:*:go:*:*" + ], + "packageName": "github.com/bishopfox/sliver", + "packageType": "go-module", + "product": "sliver", + "repo": "https://github.com/bishopfox/sliver", + "vendor": "BishopFox", + "versions": [ + { + "lessThan": "1.5.43", + "status": "affected", + "version": "1.5.26", + "versionType": "custom" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file