Skip to content

Commit 80aa4be

Browse files
Advisory Database Sync
1 parent 7b74c02 commit 80aa4be

58 files changed

Lines changed: 1660 additions & 8 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/unreviewed/2026/05/GHSA-76ww-43j5-78x5/GHSA-76ww-43j5-78x5.json

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-76ww-43j5-78x5",
4-
"modified": "2026-06-30T03:36:53Z",
4+
"modified": "2026-08-19T06:31:16Z",
55
"published": "2026-05-29T12:31:25Z",
66
"aliases": [
77
"CVE-2026-42965"
@@ -19,6 +19,18 @@
1919
"type": "ADVISORY",
2020
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42965"
2121
},
22+
{
23+
"type": "WEB",
24+
"url": "https://access.redhat.com/errata/RHSA-2026:54583"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://access.redhat.com/errata/RHSA-2026:54602"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://access.redhat.com/errata/RHSA-2026:54770"
33+
},
2234
{
2335
"type": "WEB",
2436
"url": "https://access.redhat.com/security/cve/CVE-2026-42965"

advisories/unreviewed/2026/07/GHSA-f48p-mg4r-fhww/GHSA-f48p-mg4r-fhww.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-f48p-mg4r-fhww",
4-
"modified": "2026-08-14T03:31:24Z",
4+
"modified": "2026-08-19T06:31:16Z",
55
"published": "2026-07-09T12:30:28Z",
66
"aliases": [
77
"CVE-2026-59692"
@@ -55,6 +55,10 @@
5555
"type": "WEB",
5656
"url": "https://access.redhat.com/errata/RHSA-2026:54752"
5757
},
58+
{
59+
"type": "WEB",
60+
"url": "https://access.redhat.com/errata/RHSA-2026:56658"
61+
},
5862
{
5963
"type": "WEB",
6064
"url": "https://access.redhat.com/security/cve/CVE-2026-59692"

advisories/unreviewed/2026/07/GHSA-fvwj-j79q-57v7/GHSA-fvwj-j79q-57v7.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-fvwj-j79q-57v7",
4-
"modified": "2026-07-22T21:31:54Z",
4+
"modified": "2026-08-19T06:31:16Z",
55
"published": "2026-07-21T15:30:43Z",
66
"aliases": [
77
"CVE-2026-59846"
@@ -23,6 +23,10 @@
2323
"type": "WEB",
2424
"url": "https://access.redhat.com/errata/RHSA-2026:42922"
2525
},
26+
{
27+
"type": "WEB",
28+
"url": "https://access.redhat.com/errata/RHSA-2026:55855"
29+
},
2630
{
2731
"type": "WEB",
2832
"url": "https://access.redhat.com/security/cve/CVE-2026-59846"

advisories/unreviewed/2026/07/GHSA-g4ff-54hw-hj6r/GHSA-g4ff-54hw-hj6r.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-g4ff-54hw-hj6r",
4-
"modified": "2026-08-14T03:31:24Z",
4+
"modified": "2026-08-19T06:31:16Z",
55
"published": "2026-07-09T12:30:28Z",
66
"aliases": [
77
"CVE-2026-59691"
@@ -55,6 +55,10 @@
5555
"type": "WEB",
5656
"url": "https://access.redhat.com/errata/RHSA-2026:54752"
5757
},
58+
{
59+
"type": "WEB",
60+
"url": "https://access.redhat.com/errata/RHSA-2026:56658"
61+
},
5862
{
5963
"type": "WEB",
6064
"url": "https://access.redhat.com/security/cve/CVE-2026-59691"

advisories/unreviewed/2026/07/GHSA-jp6g-7mqj-wj53/GHSA-jp6g-7mqj-wj53.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-jp6g-7mqj-wj53",
4-
"modified": "2026-07-22T21:31:54Z",
4+
"modified": "2026-08-19T06:31:16Z",
55
"published": "2026-07-21T15:30:44Z",
66
"aliases": [
77
"CVE-2026-59849"
@@ -23,6 +23,10 @@
2323
"type": "WEB",
2424
"url": "https://access.redhat.com/errata/RHSA-2026:42922"
2525
},
26+
{
27+
"type": "WEB",
28+
"url": "https://access.redhat.com/errata/RHSA-2026:55855"
29+
},
2630
{
2731
"type": "WEB",
2832
"url": "https://access.redhat.com/security/cve/CVE-2026-59849"

advisories/unreviewed/2026/07/GHSA-x94w-cg8g-g593/GHSA-x94w-cg8g-g593.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-x94w-cg8g-g593",
4-
"modified": "2026-07-22T21:31:48Z",
4+
"modified": "2026-08-19T06:31:16Z",
55
"published": "2026-07-21T12:33:36Z",
66
"aliases": [
77
"CVE-2026-59842"
@@ -23,6 +23,10 @@
2323
"type": "WEB",
2424
"url": "https://access.redhat.com/errata/RHSA-2026:42922"
2525
},
26+
{
27+
"type": "WEB",
28+
"url": "https://access.redhat.com/errata/RHSA-2026:55855"
29+
},
2630
{
2731
"type": "WEB",
2832
"url": "https://access.redhat.com/security/cve/CVE-2026-59842"
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-28r4-82c9-hfh7",
4+
"modified": "2026-08-19T06:31:17Z",
5+
"published": "2026-08-19T06:31:17Z",
6+
"aliases": [
7+
"CVE-2026-14826"
8+
],
9+
"details": "The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14826"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://wpscan.com/vulnerability/bb9cac20-4df5-4834-89f0-746a5eab20ea"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-08-19T06:17:33Z"
28+
}
29+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2x6x-6h49-pf6q",
4+
"modified": "2026-08-19T06:31:18Z",
5+
"published": "2026-08-19T06:31:18Z",
6+
"aliases": [
7+
"CVE-2026-19406"
8+
],
9+
"details": "The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19406"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://wpscan.com/vulnerability/53cfb207-8f26-438c-a928-bc9271f312f0"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-08-19T06:17:39Z"
28+
}
29+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-34m6-mf7c-4crh",
4+
"modified": "2026-08-19T06:31:18Z",
5+
"published": "2026-08-19T06:31:18Z",
6+
"aliases": [
7+
"CVE-2026-19417"
8+
],
9+
"details": "The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19417"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://wpscan.com/vulnerability/4270b160-cbb8-46b2-853c-927651ca16bf"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-08-19T06:17:40Z"
28+
}
29+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-36w4-4687-hhqj",
4+
"modified": "2026-08-19T06:31:17Z",
5+
"published": "2026-08-19T06:31:17Z",
6+
"aliases": [
7+
"CVE-2026-16617"
8+
],
9+
"details": "The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16617"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://wpscan.com/vulnerability/fc51a940-8e67-45d0-b47d-b16da288ebb3"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-08-19T06:17:35Z"
28+
}
29+
}

0 commit comments

Comments
 (0)