Auto-Update: 2025-02-01T21:00:19.461902+00:00

This commit is contained in:
cad-safe-bot 2025-02-01 21:03:49 +00:00
parent 6765b89c28
commit 29cdecf40f
5 changed files with 296 additions and 11 deletions

View File

@ -2,13 +2,13 @@
"id": "CVE-2024-13021",
"sourceIdentifier": "cna@vuldb.com",
"published": "2024-12-29T20:15:05.043",
"lastModified": "2024-12-30T18:15:08.877",
"lastModified": "2025-02-01T19:15:07.850",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability, which was classified as problematic, has been found in SourceCodester Road Accident Map Marker 1.0. Affected by this issue is some unknown functionality of the file /endpoint/add-mark.php. The manipulation of the argument mark_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well."
"value": "A vulnerability, which was classified as problematic, has been found in SourceCodester Road Accident Map Marker 1.0. Affected by this issue is some unknown functionality of the file /endpoint/add-mark.php. The manipulation of the argument mark_name/details leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well."
},
{
"lang": "es",

View File

@ -0,0 +1,141 @@
{
"id": "CVE-2025-0949",
"sourceIdentifier": "cna@vuldb.com",
"published": "2025-02-01T19:15:08.990",
"lastModified": "2025-02-01T19:15:08.990",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file partview.php. The manipulation of the argument typeid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"vulnerableSystemConfidentiality": "LOW",
"vulnerableSystemIntegrity": "LOW",
"vulnerableSystemAvailability": "LOW",
"subsequentSystemConfidentiality": "NONE",
"subsequentSystemIntegrity": "NONE",
"subsequentSystemAvailability": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirements": "NOT_DEFINED",
"integrityRequirements": "NOT_DEFINED",
"availabilityRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnerableSystemConfidentiality": "NOT_DEFINED",
"modifiedVulnerableSystemIntegrity": "NOT_DEFINED",
"modifiedVulnerableSystemAvailability": "NOT_DEFINED",
"modifiedSubsequentSystemConfidentiality": "NOT_DEFINED",
"modifiedSubsequentSystemIntegrity": "NOT_DEFINED",
"modifiedSubsequentSystemAvailability": "NOT_DEFINED",
"safety": "NOT_DEFINED",
"automatable": "NOT_DEFINED",
"recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED"
}
}
],
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 2.8,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"baseScore": 6.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://github.com/magic2353112890/cve/issues/7",
"source": "cna@vuldb.com"
},
{
"url": "https://itsourcecode.com/",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.294304",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.294304",
"source": "cna@vuldb.com"
}
]
}

View File

@ -0,0 +1,141 @@
{
"id": "CVE-2025-0950",
"sourceIdentifier": "cna@vuldb.com",
"published": "2025-02-01T20:15:26.167",
"lastModified": "2025-02-01T20:15:26.167",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file staffview.php. The manipulation of the argument staffid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"vulnerableSystemConfidentiality": "LOW",
"vulnerableSystemIntegrity": "LOW",
"vulnerableSystemAvailability": "LOW",
"subsequentSystemConfidentiality": "NONE",
"subsequentSystemIntegrity": "NONE",
"subsequentSystemAvailability": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirements": "NOT_DEFINED",
"integrityRequirements": "NOT_DEFINED",
"availabilityRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnerableSystemConfidentiality": "NOT_DEFINED",
"modifiedVulnerableSystemIntegrity": "NOT_DEFINED",
"modifiedVulnerableSystemAvailability": "NOT_DEFINED",
"modifiedSubsequentSystemConfidentiality": "NOT_DEFINED",
"modifiedSubsequentSystemIntegrity": "NOT_DEFINED",
"modifiedSubsequentSystemAvailability": "NOT_DEFINED",
"safety": "NOT_DEFINED",
"automatable": "NOT_DEFINED",
"recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED"
}
}
],
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 2.8,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"baseScore": 6.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://github.com/magic2353112890/cve/issues/7",
"source": "cna@vuldb.com"
},
{
"url": "https://itsourcecode.com/",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.294305",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.294305",
"source": "cna@vuldb.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2025-02-01T19:00:20.487160+00:00
2025-02-01T21:00:19.461902+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2025-02-01T18:15:27.087000+00:00
2025-02-01T20:15:26.167000+00:00
```
### Last Data Feed Release
@ -33,21 +33,22 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
279756
279758
```
### CVEs added in the last Commit
Recently added CVEs: `2`
- [CVE-2025-0947](CVE-2025/CVE-2025-09xx/CVE-2025-0947.json) (`2025-02-01T17:15:08.207`)
- [CVE-2025-0948](CVE-2025/CVE-2025-09xx/CVE-2025-0948.json) (`2025-02-01T18:15:27.087`)
- [CVE-2025-0949](CVE-2025/CVE-2025-09xx/CVE-2025-0949.json) (`2025-02-01T19:15:08.990`)
- [CVE-2025-0950](CVE-2025/CVE-2025-09xx/CVE-2025-0950.json) (`2025-02-01T20:15:26.167`)
### CVEs modified in the last Commit
Recently modified CVEs: `0`
Recently modified CVEs: `1`
- [CVE-2024-13021](CVE-2024/CVE-2024-130xx/CVE-2024-13021.json) (`2025-02-01T19:15:07.850`)
## Download and Usage

View File

@ -245968,7 +245968,7 @@ CVE-2024-13018,0,0,33a4ebf1645d8c63e45760ee075555d921a825bccf27f84a9752563c35f6b
CVE-2024-13019,0,0,e5ad88c269caf1eda2c0e433efd9e16af60c4b48a53789c861cfcc6c1818d7d6,2024-12-30T19:15:06.847000
CVE-2024-1302,0,0,50e21539c22b43b4db748f33a4680786d0cd3b39c9a7a5fc858bc75c33660782,2024-11-21T08:50:16.467000
CVE-2024-13020,0,0,b18d1df78883ef9551ccbd20bdbcc8078b4e2c83db1c235e3e8b397ebf60cc55,2024-12-30T19:15:07.537000
CVE-2024-13021,0,0,b2125a08a6d336198980c4854d3c2315464df5ac6132725f500803e9c62b5bfe,2024-12-30T18:15:08.877000
CVE-2024-13021,0,1,e401a77980fac909f19d47cc3c1c7289cfaeeaf335646b6ebb44ac1c48b5d8e7,2025-02-01T19:15:07.850000
CVE-2024-13022,0,0,90bb63d1bc90626e0499ce8896752c6e5ed50822b829721b8cf1b7b0080afd11,2024-12-29T20:15:05.980000
CVE-2024-13023,0,0,d029eb35c9bdf0045e63a954d82e8162ce974ac9ca1940b6ad8d92005bea27e7,2024-12-29T21:15:06.020000
CVE-2024-13024,0,0,2d443fd15bbce33c05ab26d4fb4c87b3a41715b85dfb24d19e706acdb51ba0ef,2024-12-29T21:15:06.220000
@ -278256,8 +278256,10 @@ CVE-2025-0943,0,0,d4beefef9f033db94e741551c1c44f80d0a15c5f160db1305b65e51b448ddc
CVE-2025-0944,0,0,466fd010105c25b8c1cb799c1a662d0d3d59d16cdf2170bb14c4a5fe916ca896,2025-02-01T13:15:23.027000
CVE-2025-0945,0,0,c0dd6e95d513219a7236596b3342d0d9b78fd732ae49d117e638d1e71c2f9eba,2025-02-01T15:15:08.320000
CVE-2025-0946,0,0,cdf09a9e00f9b09af1120c064387c6b9fc703bcb0a087c9cb861518902d040fb,2025-02-01T16:15:27.180000
CVE-2025-0947,1,1,18c6447ef4b3d89e32f0b02a151ab03f71c50f9ed501c23e2d75ca2822d337cb,2025-02-01T17:15:08.207000
CVE-2025-0948,1,1,b3e239e0b0bce38bd09a0dba860247a5fda8e579caf9c57cdfe9d35308906897,2025-02-01T18:15:27.087000
CVE-2025-0947,0,0,18c6447ef4b3d89e32f0b02a151ab03f71c50f9ed501c23e2d75ca2822d337cb,2025-02-01T17:15:08.207000
CVE-2025-0948,0,0,b3e239e0b0bce38bd09a0dba860247a5fda8e579caf9c57cdfe9d35308906897,2025-02-01T18:15:27.087000
CVE-2025-0949,1,1,bbbcf0332f588cdfc0cbe42ff6f97aa1e222ce3fa7893528a5a23bbcb3b1415a,2025-02-01T19:15:08.990000
CVE-2025-0950,1,1,d0a581246e8da6f5efefddad90bec069aea6bc29a1173d1f9e38dd153c08b340,2025-02-01T20:15:26.167000
CVE-2025-20014,0,0,708b5660539e4ab2830a732991daead462d3c8df88b4205953edf58b017cb8b0,2025-01-29T20:15:35.207000
CVE-2025-20016,0,0,6fccb84eb01c2cd66b422e82777f9738bfe5004121e1b551d0ae454724543c0e,2025-01-14T10:15:07.500000
CVE-2025-20033,0,0,6c60c85e451f1d6db70378d678ddf83dacc7c823ecfb493748ed6d94114eff49,2025-01-09T07:15:28.450000

Can't render this file because it is too large.