Auto-Update: 2025-05-19T08:00:20.660903+00:00

This commit is contained in:
cad-safe-bot 2025-05-19 08:03:56 +00:00
parent 4d52855e6a
commit 1f860df3a5
13 changed files with 843 additions and 17 deletions

View File

@ -0,0 +1,21 @@
{
"id": "CVE-2025-1625",
"sourceIdentifier": "contact@wpscan.com",
"published": "2025-05-19T06:15:17.900",
"lastModified": "2025-05-19T06:15:17.900",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks."
}
],
"metrics": {},
"references": [
{
"url": "https://wpscan.com/vulnerability/288208c4-e9ca-4b79-88e7-fb415a726fce/",
"source": "contact@wpscan.com"
}
]
}

View File

@ -0,0 +1,21 @@
{
"id": "CVE-2025-1626",
"sourceIdentifier": "contact@wpscan.com",
"published": "2025-05-19T06:15:18.863",
"lastModified": "2025-05-19T06:15:18.863",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks."
}
],
"metrics": {},
"references": [
{
"url": "https://wpscan.com/vulnerability/f00d86f1-7ff9-4001-af16-989358d811a8/",
"source": "contact@wpscan.com"
}
]
}

View File

@ -0,0 +1,21 @@
{
"id": "CVE-2025-1627",
"sourceIdentifier": "contact@wpscan.com",
"published": "2025-05-19T06:15:18.980",
"lastModified": "2025-05-19T06:15:18.980",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks."
}
],
"metrics": {},
"references": [
{
"url": "https://wpscan.com/vulnerability/31b2292b-1ea7-4d63-ad65-0366e2c05dd3/",
"source": "contact@wpscan.com"
}
]
}

View File

@ -0,0 +1,21 @@
{
"id": "CVE-2025-2524",
"sourceIdentifier": "contact@wpscan.com",
"published": "2025-05-19T06:15:19.107",
"lastModified": "2025-05-19T06:15:19.107",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)."
}
],
"metrics": {},
"references": [
{
"url": "https://wpscan.com/vulnerability/6e89ad2b-f12e-4b49-b34e-8da7d30629cd/",
"source": "contact@wpscan.com"
}
]
}

View File

@ -0,0 +1,21 @@
{
"id": "CVE-2025-2560",
"sourceIdentifier": "contact@wpscan.com",
"published": "2025-05-19T06:15:19.233",
"lastModified": "2025-05-19T06:15:19.233",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)."
}
],
"metrics": {},
"references": [
{
"url": "https://wpscan.com/vulnerability/2adaa55a-4a6d-40ca-ae19-fcb82420894a/",
"source": "contact@wpscan.com"
}
]
}

View File

@ -0,0 +1,21 @@
{
"id": "CVE-2025-2561",
"sourceIdentifier": "contact@wpscan.com",
"published": "2025-05-19T06:15:19.350",
"lastModified": "2025-05-19T06:15:19.350",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)."
}
],
"metrics": {},
"references": [
{
"url": "https://wpscan.com/vulnerability/4a2074a3-a479-4473-92fb-04397f20dd86/",
"source": "contact@wpscan.com"
}
]
}

View File

@ -0,0 +1,104 @@
{
"id": "CVE-2025-4477",
"sourceIdentifier": "twcert@cert.org.tw",
"published": "2025-05-19T06:15:19.470",
"lastModified": "2025-05-19T06:15:19.470",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with intermediate privileges to escalate their privileges to highest administrator level through a specific API."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "twcert@cert.org.tw",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"subAvailabilityImpact": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirement": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"availabilityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED"
}
}
],
"cvssMetricV31": [
{
"source": "twcert@cert.org.tw",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "twcert@cert.org.tw",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"references": [
{
"url": "https://www.twcert.org.tw/en/cp-139-10130-c0959-2.html",
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-10129-18ea3-1.html",
"source": "twcert@cert.org.tw"
}
]
}

View File

@ -0,0 +1,145 @@
{
"id": "CVE-2025-4913",
"sourceIdentifier": "cna@vuldb.com",
"published": "2025-05-19T06:15:19.790",
"lastModified": "2025-05-19T06:15:19.790",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnAvailabilityImpact": "LOW",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"subAvailabilityImpact": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirement": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"availabilityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED"
}
}
],
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"baseScore": 7.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://github.com/Pjwww13447/pjwww/issues/15",
"source": "cna@vuldb.com"
},
{
"url": "https://phpgurukul.com/",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.309470",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.309470",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.579095",
"source": "cna@vuldb.com"
}
]
}

View File

@ -0,0 +1,145 @@
{
"id": "CVE-2025-4914",
"sourceIdentifier": "cna@vuldb.com",
"published": "2025-05-19T06:15:20.243",
"lastModified": "2025-05-19T06:15:20.243",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnAvailabilityImpact": "LOW",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"subAvailabilityImpact": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirement": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"availabilityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED"
}
}
],
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"baseScore": 7.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://github.com/Pjwww13447/pjwww/issues/16",
"source": "cna@vuldb.com"
},
{
"url": "https://phpgurukul.com/",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.309471",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.309471",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.579096",
"source": "cna@vuldb.com"
}
]
}

View File

@ -0,0 +1,145 @@
{
"id": "CVE-2025-4915",
"sourceIdentifier": "cna@vuldb.com",
"published": "2025-05-19T07:15:17.823",
"lastModified": "2025-05-19T07:15:17.823",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/auto-taxi-entry-detail.php. The manipulation of the argument price leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnAvailabilityImpact": "LOW",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"subAvailabilityImpact": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirement": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"availabilityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED"
}
}
],
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"baseScore": 7.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://github.com/Pjwww13447/pjwww/issues/17",
"source": "cna@vuldb.com"
},
{
"url": "https://phpgurukul.com/",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.309472",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.309472",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.579097",
"source": "cna@vuldb.com"
}
]
}

View File

@ -0,0 +1,145 @@
{
"id": "CVE-2025-4916",
"sourceIdentifier": "cna@vuldb.com",
"published": "2025-05-19T07:15:18.067",
"lastModified": "2025-05-19T07:15:18.067",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnAvailabilityImpact": "LOW",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"subAvailabilityImpact": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirement": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"availabilityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED"
}
}
],
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"baseScore": 7.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://github.com/Pjwww13447/pjwww/issues/18",
"source": "cna@vuldb.com"
},
{
"url": "https://phpgurukul.com/",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.309473",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.309473",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.579098",
"source": "cna@vuldb.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2025-05-19T06:00:19.420430+00:00
2025-05-19T08:00:20.660903+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2025-05-19T05:15:18.387000+00:00
2025-05-19T07:15:18.067000+00:00
```
### Last Data Feed Release
@ -33,25 +33,30 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
294581
294592
```
### CVEs added in the last Commit
Recently added CVEs: `5`
Recently added CVEs: `11`
- [CVE-2025-2892](CVE-2025/CVE-2025-28xx/CVE-2025-2892.json) (`2025-05-19T05:15:17.927`)
- [CVE-2025-4909](CVE-2025/CVE-2025-49xx/CVE-2025-4909.json) (`2025-05-19T04:15:42.083`)
- [CVE-2025-4910](CVE-2025/CVE-2025-49xx/CVE-2025-4910.json) (`2025-05-19T04:15:46.183`)
- [CVE-2025-4911](CVE-2025/CVE-2025-49xx/CVE-2025-4911.json) (`2025-05-19T05:15:18.160`)
- [CVE-2025-4912](CVE-2025/CVE-2025-49xx/CVE-2025-4912.json) (`2025-05-19T05:15:18.387`)
- [CVE-2025-1625](CVE-2025/CVE-2025-16xx/CVE-2025-1625.json) (`2025-05-19T06:15:17.900`)
- [CVE-2025-1626](CVE-2025/CVE-2025-16xx/CVE-2025-1626.json) (`2025-05-19T06:15:18.863`)
- [CVE-2025-1627](CVE-2025/CVE-2025-16xx/CVE-2025-1627.json) (`2025-05-19T06:15:18.980`)
- [CVE-2025-2524](CVE-2025/CVE-2025-25xx/CVE-2025-2524.json) (`2025-05-19T06:15:19.107`)
- [CVE-2025-2560](CVE-2025/CVE-2025-25xx/CVE-2025-2560.json) (`2025-05-19T06:15:19.233`)
- [CVE-2025-2561](CVE-2025/CVE-2025-25xx/CVE-2025-2561.json) (`2025-05-19T06:15:19.350`)
- [CVE-2025-4477](CVE-2025/CVE-2025-44xx/CVE-2025-4477.json) (`2025-05-19T06:15:19.470`)
- [CVE-2025-4913](CVE-2025/CVE-2025-49xx/CVE-2025-4913.json) (`2025-05-19T06:15:19.790`)
- [CVE-2025-4914](CVE-2025/CVE-2025-49xx/CVE-2025-4914.json) (`2025-05-19T06:15:20.243`)
- [CVE-2025-4915](CVE-2025/CVE-2025-49xx/CVE-2025-4915.json) (`2025-05-19T07:15:17.823`)
- [CVE-2025-4916](CVE-2025/CVE-2025-49xx/CVE-2025-4916.json) (`2025-05-19T07:15:18.067`)
### CVEs modified in the last Commit
Recently modified CVEs: `1`
Recently modified CVEs: `0`
- [CVE-2024-21538](CVE-2024/CVE-2024-215xx/CVE-2024-21538.json) (`2025-05-19T04:15:22.287`)
## Download and Usage

View File

@ -250893,7 +250893,7 @@ CVE-2024-21534,0,0,d48dddf4dea9b7661494f0504fa94cdcd27b98dfb55f8a57227d805bc473c
CVE-2024-21535,0,0,af117382fc22be74e34dfd1ea566b513c64b3b156e9a19fd2886f56ff9e62476,2024-10-17T20:36:29.213000
CVE-2024-21536,0,0,12c83b03efaaa3cc2890c754edcace2dd7ffc8b3d03f735b6e31c62550b0254b,2024-11-01T18:03:15.897000
CVE-2024-21537,0,0,434d7d2766b91e13cca78a0a8ea1a46a74136bc67ef591981914fba4f50ec56c,2024-11-01T12:57:03.417000
CVE-2024-21538,0,1,7b94a727fdeac75257263fb3e9d527d10d44838129608f96c198b7cc2209af4c,2025-05-19T04:15:22.287000
CVE-2024-21538,0,0,7b94a727fdeac75257263fb3e9d527d10d44838129608f96c198b7cc2209af4c,2025-05-19T04:15:22.287000
CVE-2024-21539,0,0,5b71b48f136ea0a133f42f5e9ff41239f19728230b6ea876d025e715b63e91d7,2024-11-19T21:57:32.967000
CVE-2024-2154,0,0,ffeeac95960a7865d135456d7433827b762c9eee41da0ca2ab259c73402ce4ce,2024-12-20T19:38:32.983000
CVE-2024-21540,0,0,ca361900c1eaa9a3b1242a94b8aed82eaba7c8170c10a4efa35cbfaad6b1984c,2024-11-17T09:15:11.853000
@ -283281,6 +283281,9 @@ CVE-2025-1621,0,0,8a787c15f9017e755d671c57e2fae1b1ecaa7e8181706c3b4fe61a0640bed0
CVE-2025-1622,0,0,83bc83f61fc38b85baa59981c2f3dbfd80063a5464aab043b7d9e7050f34215b,2025-04-02T12:32:52.523000
CVE-2025-1623,0,0,e22cc6178a42a7d6bd5b6ab3a263f749cee878d859c3f3cb16c7aff9fcdaac70,2025-04-02T12:32:24.480000
CVE-2025-1624,0,0,ef176ff080c4b3a527e42c44f790cc5882cbfb4415ab47bfafda4be34813a6c9,2025-04-02T12:32:04.340000
CVE-2025-1625,1,1,e05f7b812baed6ac20bd64b76501bf5ab3796fc7c21a794e9b5d0cb5a40b6368,2025-05-19T06:15:17.900000
CVE-2025-1626,1,1,a0ee91af66060eb73eab198dd6b8cc4e3f6dfd6e8c1204025e6db136cf5650e7,2025-05-19T06:15:18.863000
CVE-2025-1627,1,1,66b24dcdbfc75d2b00fd1c08305da957b8ac9a7c1d4012c0ec20abac1bee1b57,2025-05-19T06:15:18.980000
CVE-2025-1628,0,0,0981be15b6355fe96e6cf6533415aadaefca54b32ab4ef2345058038a2f7e6bb,2025-03-19T23:15:12.783000
CVE-2025-1629,0,0,98e40b68e5632eb91f4db527ca6594bcd0a0e66070641abd7d2f14eb9bdef0c3,2025-02-24T05:15:11.280000
CVE-2025-1632,0,0,73963594ec349af4ff5563baefa2275473270d101d132ae7dd238c3c85b0ecda,2025-03-25T15:41:41.683000
@ -287584,6 +287587,7 @@ CVE-2025-25227,0,0,14dde9d48b40850eb1a2d705436b8ead1fc46d2a4e1905b71e2c6de779c3c
CVE-2025-25228,0,0,17bc5cf18d7274f66291cb5819d285eabce13f59fa5519c126322bc00ededd23,2025-05-06T20:15:26.073000
CVE-2025-25230,0,0,cde429db29668f2208cc0ac9bf6a0bbe82efea6a0284bedcc8e98cb183173346,2025-04-17T20:21:48.243000
CVE-2025-25234,0,0,26b863422c4d0e43f33b733e614cf16546d205c05bf67032461c649336371231,2025-04-21T18:35:58.613000
CVE-2025-2524,1,1,f4a49537ce68df042e79b1cb3b4ca2ccdd96b830cbf1227b71acccb8f46cbcbc,2025-05-19T06:15:19.107000
CVE-2025-25241,0,0,f70d628c4466ad6abe844cd65a2579f5c9e5af240d0c56eadc1f05ff31a52618,2025-02-18T18:15:34.967000
CVE-2025-25242,0,0,9434714e72888d1a52e5bad48430408baa107619f6e4dcba8f508d71d8cfd58f,2025-03-11T01:15:34.777000
CVE-2025-25243,0,0,906f44310c3cdd164cd7aafcd2415e522d55d23269db0ed5b7f0708c0da72aa0,2025-02-18T18:15:35.160000
@ -287750,9 +287754,11 @@ CVE-2025-2559,0,0,e0a1ec52fcee197642d94bd63e1278a00066cfd7daa56d8679b3fb30d47c24
CVE-2025-25590,0,0,3893b0a4da36be48d36967b7837bf6fae4ec31547efd1c3211b9404b64ed4014,2025-03-19T19:15:45.640000
CVE-2025-25595,0,0,fed1db19038d4b73f5895de99c0193dd0437928c86ea4f6762661a5574f5f9ac,2025-04-01T20:38:28.603000
CVE-2025-25598,0,0,97b7c491c3636dfe02438cb323583c05678dcf453afda217f0aaabb9e8d0908a,2025-04-03T16:36:30.420000
CVE-2025-2560,1,1,d1dd63fa0581882af31a7c380b768e97f818ad194ed3ad11c8fe624a75656c6f,2025-05-19T06:15:19.233000
CVE-2025-25604,0,0,0c637c9d94b9d81b522887cf8f7a7bc4df6564c0228527fd87e291ecbec0e7ee,2025-04-04T15:30:47.660000
CVE-2025-25605,0,0,f30900bd813d031d8be80147a5bcf9a3bf2b0e08d56dacb4986982bce513de9d,2025-04-04T15:29:44.367000
CVE-2025-25609,0,0,353094876441323d490e83a48523be60d5eb9eb9c98e0de6ee9312f642e87e4a,2025-04-03T15:37:42.047000
CVE-2025-2561,1,1,d6af8c0c0cf588f7aac3bb2e5cc87fb70a45b5e9b21ed79a6a2df6325b521300,2025-05-19T06:15:19.350000
CVE-2025-25610,0,0,e0689668b156fca91ef1f105b78072f67038706b216940f4601acf0901e8570f,2025-04-03T15:37:48.043000
CVE-2025-25612,0,0,3d5ba8d95bd4cf5257a75851925a661e44bd5b9835f17ccfa2c4bade6d51d6df,2025-03-17T18:15:21.300000
CVE-2025-25614,0,0,a061fd28fa65ddcfb4ed8f2a56829d30e68a6722cf38abd81a56f36279e7ce01,2025-03-10T20:15:14.280000
@ -289423,7 +289429,7 @@ CVE-2025-28916,0,0,d3414a3d6aa8011b44c8a028516f43a6a4fbe2fe98478e47a933c00af4ebd
CVE-2025-28917,0,0,e67e97f24c984128f66143419f730643f0c93a942f9e07e45adf096399200416,2025-03-27T16:45:27.850000
CVE-2025-28918,0,0,fdafb0cadbdc8702c914c4b18f3da98b888fc45b917f3a8f53be26fb090f5d81,2025-03-11T21:15:49.477000
CVE-2025-28919,0,0,e6672d722a11dcfca58aa36b7a671c1f514123681fc1ee91277ee2808176f84d,2025-03-11T21:15:49.623000
CVE-2025-2892,1,1,b166ef57647e2ab537b081f2fcf87d433ca3ec5dc05fd212bd0687c086999207,2025-05-19T05:15:17.927000
CVE-2025-2892,0,0,b166ef57647e2ab537b081f2fcf87d433ca3ec5dc05fd212bd0687c086999207,2025-05-19T05:15:17.927000
CVE-2025-28920,0,0,1b39516a58e980ceafff6c35c5258f2defea2070ea7dcb67965a1cfa09291c9e,2025-03-11T21:15:49.780000
CVE-2025-28921,0,0,b3b52a8f0a2431089fa08adb8a54ce8cd32f2c33bbe78ebb9f321e3e7fffa0a4,2025-03-27T16:45:27.850000
CVE-2025-28922,0,0,2a34783987ce2da8a6d7f97c25f9b57365e5fab3264e58b957c07ae86bb16f03,2025-03-11T21:15:49.930000
@ -293544,6 +293550,7 @@ CVE-2025-4473,0,0,33a19d086c9413e22104c537940ce7696b1e1d5a3de7446354d1c9f589545c
CVE-2025-4474,0,0,521383e1283ef4d1ff9625642b1a5dc07f9413290fdec0a9acd1e250cd6861e3,2025-05-13T19:35:18.080000
CVE-2025-4475,0,0,14fd175cd338c800e457595a2058771799c1f3a8f146feda826cf08c0646f5cd,2025-05-08T23:15:53.667000
CVE-2025-4476,0,0,4e51a5eb6068ff0a442d12685bd0d68c88e097c0bea28b519b02068a7fbb226d,2025-05-16T18:16:10.970000
CVE-2025-4477,1,1,ddf3b5ef2cc835674972a5c6272033a929e3b45caf44e70422008c9777bda151,2025-05-19T06:15:19.470000
CVE-2025-4478,0,0,03ef951cd0573eda63caa67cae234f3405180868b84b3c173d78574de27ad014,2025-05-16T15:15:48.630000
CVE-2025-4480,0,0,be672d537a11a289b7d1b98f279ab333277916180d26385e3402215687d48a25,2025-05-16T15:34:40.510000
CVE-2025-4481,0,0,0fe1448ef925f4ba16b8e05736b526de574a9ed7259d4944c0e5684d261dd60d,2025-05-16T15:34:18.840000
@ -294572,10 +294579,14 @@ CVE-2025-4905,0,0,e33f14f3ea647335fe946251421b3003edf997fb295ca2e77ce2e6e934d175
CVE-2025-4906,0,0,998aed1421a78b034db51580a0d30b32319e3e0389ec3542ee4085b9395c8d6d,2025-05-19T03:15:20.853000
CVE-2025-4907,0,0,b2dd1fe12d432cf475b9d97670563354635a0469cafbfa90e1f40e3baef38ad9,2025-05-19T03:15:21.377000
CVE-2025-4908,0,0,29032c2c2dbc6c8121adce4f33c3d8abc5389653f42fe082a8c96a2d679143e4,2025-05-19T03:15:21.567000
CVE-2025-4909,1,1,b6c979415b402f0da3380eb7d12291a9993633c99bb58d3537bbe37169bad115,2025-05-19T04:15:42.083000
CVE-2025-4910,1,1,5979ba1f8af2ee2af2a992ecc945f06c57fbd5d3bc558aa6804bc56d0e562076,2025-05-19T04:15:46.183000
CVE-2025-4911,1,1,a70e6a977628107721a46a722af94401345785bc1ed752a2f67c2aad7a4f5664,2025-05-19T05:15:18.160000
CVE-2025-4912,1,1,6c04667cb64d0945f0aeb14f3d1000c7889e9d1252705011ee8be04ab67e6f96,2025-05-19T05:15:18.387000
CVE-2025-4909,0,0,b6c979415b402f0da3380eb7d12291a9993633c99bb58d3537bbe37169bad115,2025-05-19T04:15:42.083000
CVE-2025-4910,0,0,5979ba1f8af2ee2af2a992ecc945f06c57fbd5d3bc558aa6804bc56d0e562076,2025-05-19T04:15:46.183000
CVE-2025-4911,0,0,a70e6a977628107721a46a722af94401345785bc1ed752a2f67c2aad7a4f5664,2025-05-19T05:15:18.160000
CVE-2025-4912,0,0,6c04667cb64d0945f0aeb14f3d1000c7889e9d1252705011ee8be04ab67e6f96,2025-05-19T05:15:18.387000
CVE-2025-4913,1,1,c9f4e5369c150303162d9bdb3b0dbbfbb7bd44e198b5eefe41316cfa418cf2db,2025-05-19T06:15:19.790000
CVE-2025-4914,1,1,d1aeab9f9d0a2ef167ec805f3553cef3b1507722e803671b2848c718e2b97246,2025-05-19T06:15:20.243000
CVE-2025-4915,1,1,1b8b75a58bb73f17eb2ba693fb62173232aee7f43d63ac301eb568d7785e3c0a,2025-05-19T07:15:17.823000
CVE-2025-4916,1,1,226f174676c2f23a56266d9075fb3be3be569120a7ae1553af43f9e2928742a5,2025-05-19T07:15:18.067000
CVE-2025-4918,0,0,aed9091230905d5e23b7429fa901fde9cec3dc55e33ebc3f16d4831a984c7654,2025-05-18T20:15:18.997000
CVE-2025-4919,0,0,fe1492d76d2474da61ddffcc8df04fb2c66b93823ab67a78e6d777fd3dc8b8da,2025-05-18T20:15:19.097000
CVE-2025-4920,0,0,3f754dcd1f915b78f78753940c39593d2b8252e0b2ac1b3316d99c54b7913aab,2025-05-18T20:15:19.190000

Can't render this file because it is too large.