diff --git a/advisories/unreviewed/2025/01/GHSA-p89p-pvgh-v347/GHSA-p89p-pvgh-v347.json b/advisories/unreviewed/2025/01/GHSA-p89p-pvgh-v347/GHSA-p89p-pvgh-v347.json index 41bec61abf2..4acfe57cb14 100644 --- a/advisories/unreviewed/2025/01/GHSA-p89p-pvgh-v347/GHSA-p89p-pvgh-v347.json +++ b/advisories/unreviewed/2025/01/GHSA-p89p-pvgh-v347/GHSA-p89p-pvgh-v347.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-63q8-m9xc-99xg/GHSA-63q8-m9xc-99xg.json b/advisories/unreviewed/2025/02/GHSA-63q8-m9xc-99xg/GHSA-63q8-m9xc-99xg.json index 43448901af0..31f71aa89c1 100644 --- a/advisories/unreviewed/2025/02/GHSA-63q8-m9xc-99xg/GHSA-63q8-m9xc-99xg.json +++ b/advisories/unreviewed/2025/02/GHSA-63q8-m9xc-99xg/GHSA-63q8-m9xc-99xg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-rqcg-626c-3qxf/GHSA-rqcg-626c-3qxf.json b/advisories/unreviewed/2025/02/GHSA-rqcg-626c-3qxf/GHSA-rqcg-626c-3qxf.json index 6c69d8ff546..2fd0919ef07 100644 --- a/advisories/unreviewed/2025/02/GHSA-rqcg-626c-3qxf/GHSA-rqcg-626c-3qxf.json +++ b/advisories/unreviewed/2025/02/GHSA-rqcg-626c-3qxf/GHSA-rqcg-626c-3qxf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-4c44-wpv3-4f58/GHSA-4c44-wpv3-4f58.json b/advisories/unreviewed/2025/05/GHSA-4c44-wpv3-4f58/GHSA-4c44-wpv3-4f58.json new file mode 100644 index 00000000000..3886177ff12 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4c44-wpv3-4f58/GHSA-4c44-wpv3-4f58.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c44-wpv3-4f58", + "modified": "2025-05-12T03:30:26Z", + "published": "2025-05-12T03:30:26Z", + "aliases": [ + "CVE-2025-4555" + ], + "details": "The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking records, and restarting the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4555" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10109-25719-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10108-f77f5-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T03:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h3xv-8c7h-5fjq/GHSA-h3xv-8c7h-5fjq.json b/advisories/unreviewed/2025/05/GHSA-h3xv-8c7h-5fjq/GHSA-h3xv-8c7h-5fjq.json new file mode 100644 index 00000000000..47f43d99001 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h3xv-8c7h-5fjq/GHSA-h3xv-8c7h-5fjq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3xv-8c7h-5fjq", + "modified": "2025-05-12T03:30:26Z", + "published": "2025-05-12T03:30:26Z", + "aliases": [ + "CVE-2025-4554" + ], + "details": "A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/bwdates-passreports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4554" + }, + { + "type": "WEB", + "url": "https://github.com/y77-88/myCVE/issues/9" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308301" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308301" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567586" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T01:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mx8m-h62w-82vp/GHSA-mx8m-h62w-82vp.json b/advisories/unreviewed/2025/05/GHSA-mx8m-h62w-82vp/GHSA-mx8m-h62w-82vp.json new file mode 100644 index 00000000000..08b47d2015c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mx8m-h62w-82vp/GHSA-mx8m-h62w-82vp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx8m-h62w-82vp", + "modified": "2025-05-12T03:30:26Z", + "published": "2025-05-12T03:30:26Z", + "aliases": [ + "CVE-2025-4556" + ], + "details": "The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4556" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10111-b78e6-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10110-114f0-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T03:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qg79-8fm6-f6qw/GHSA-qg79-8fm6-f6qw.json b/advisories/unreviewed/2025/05/GHSA-qg79-8fm6-f6qw/GHSA-qg79-8fm6-f6qw.json new file mode 100644 index 00000000000..00070b9a09d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qg79-8fm6-f6qw/GHSA-qg79-8fm6-f6qw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg79-8fm6-f6qw", + "modified": "2025-05-12T03:30:26Z", + "published": "2025-05-12T03:30:26Z", + "aliases": [ + "CVE-2025-4557" + ], + "details": "The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4557" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10113-58c29-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10112-5de7e-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T03:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wwhv-9m6v-jg97/GHSA-wwhv-9m6v-jg97.json b/advisories/unreviewed/2025/05/GHSA-wwhv-9m6v-jg97/GHSA-wwhv-9m6v-jg97.json new file mode 100644 index 00000000000..d1fa0e51074 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wwhv-9m6v-jg97/GHSA-wwhv-9m6v-jg97.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwhv-9m6v-jg97", + "modified": "2025-05-12T03:30:26Z", + "published": "2025-05-12T03:30:26Z", + "aliases": [ + "CVE-2025-4553" + ], + "details": "A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4553" + }, + { + "type": "WEB", + "url": "https://github.com/y77-88/myCVE/issues/8" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308300" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308300" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567584" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-12T01:15:54Z" + } +} \ No newline at end of file