Skip to content

Commit fc65e92

Browse files
1 parent ac7e3ad commit fc65e92

7 files changed

Lines changed: 360 additions & 1 deletion

File tree

Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-295h-2wxv-92gx",
4+
"modified": "2026-08-20T03:32:54Z",
5+
"published": "2026-08-20T03:32:54Z",
6+
"aliases": [
7+
"CVE-2026-76783"
8+
],
9+
"details": "A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76783"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://uvxbywu62qm.feishu.cn/wiki/X1T5w8jPUinAsVkM0bhcZf4XnHe?from=from_copylink"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://vuldb.com/cve/CVE-2026-76783"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/submit/879225"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/vuln/393243"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/393243/cti"
45+
}
46+
],
47+
"database_specific": {
48+
"cwe_ids": [
49+
"CWE-74"
50+
],
51+
"severity": "MODERATE",
52+
"github_reviewed": false,
53+
"github_reviewed_at": null,
54+
"nvd_published_at": "2026-08-20T01:16:53Z"
55+
}
56+
}

advisories/unreviewed/2026/08/GHSA-2v69-2w5x-455j/GHSA-2v69-2w5x-455j.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-2v69-2w5x-455j",
4-
"modified": "2026-08-18T18:31:58Z",
4+
"modified": "2026-08-20T03:32:54Z",
55
"published": "2026-08-18T18:31:57Z",
66
"aliases": [
77
"CVE-2026-15806"
@@ -27,6 +27,10 @@
2727
"type": "WEB",
2828
"url": "https://github.com/python/cpython/pull/155696"
2929
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6"
33+
},
3034
{
3135
"type": "WEB",
3236
"url": "https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8"
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-65j8-pc6h-hh98",
4+
"modified": "2026-08-20T03:32:54Z",
5+
"published": "2026-08-20T03:32:54Z",
6+
"aliases": [
7+
"CVE-2026-76799"
8+
],
9+
"details": "A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation causes files or directories accessible. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76799"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://code-projects.org"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://raw.githubusercontent.com/anubhavv106/Security-Advisories/refs/heads/main/Login-Registration-System-login_registration_system.sql-Sensitive-Database-Disclosure.md"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/cve/CVE-2026-76799"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/submit/880056"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/393314"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://vuldb.com/vuln/393314/cti"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-425"
54+
],
55+
"severity": "MODERATE",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-08-20T02:16:21Z"
59+
}
60+
}
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-cqr6-46h6-qqxj",
4+
"modified": "2026-08-20T03:32:55Z",
5+
"published": "2026-08-20T03:32:55Z",
6+
"aliases": [
7+
"CVE-2026-76800"
8+
],
9+
"details": "A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Executing a manipulation of the argument uploadfile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been published and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76800"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://uvxbywu62qm.feishu.cn/wiki/TKqDwJGYaiBVXpk3EtFcdjRDnsg?from=from_copylink"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://vuldb.com/cve/CVE-2026-76800"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/submit/880081"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/vuln/393317"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/393317/cti"
45+
}
46+
],
47+
"database_specific": {
48+
"cwe_ids": [
49+
"CWE-284"
50+
],
51+
"severity": "LOW",
52+
"github_reviewed": false,
53+
"github_reviewed_at": null,
54+
"nvd_published_at": "2026-08-20T03:16:23Z"
55+
}
56+
}
Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,72 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-p53p-vh92-qhpp",
4+
"modified": "2026-08-20T03:32:54Z",
5+
"published": "2026-08-20T03:32:54Z",
6+
"aliases": [
7+
"CVE-2026-76795"
8+
],
9+
"details": "A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of the file /api of the component REST API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.0 will fix this issue. The identifier of the patch is 96448894cc93ccecb0bdcbf263a9d25390a8455e. Upgrading the affected component is advised.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76795"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/AeternaLabsHQ/pullmd/issues/41"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/AeternaLabsHQ/pullmd/pull/42"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/AeternaLabsHQ/pullmd/commit/96448894cc93ccecb0bdcbf263a9d25390a8455e"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/AeternaLabsHQ/pullmd"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://github.com/AeternaLabsHQ/pullmd/releases/tag/v3.3.0"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://vuldb.com/cve/CVE-2026-76795"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://vuldb.com/submit/879954"
53+
},
54+
{
55+
"type": "WEB",
56+
"url": "https://vuldb.com/vuln/393282"
57+
},
58+
{
59+
"type": "WEB",
60+
"url": "https://vuldb.com/vuln/393282/cti"
61+
}
62+
],
63+
"database_specific": {
64+
"cwe_ids": [
65+
"CWE-918"
66+
],
67+
"severity": "MODERATE",
68+
"github_reviewed": false,
69+
"github_reviewed_at": null,
70+
"nvd_published_at": "2026-08-20T01:16:54Z"
71+
}
72+
}
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-v6g5-xxrx-m495",
4+
"modified": "2026-08-20T03:32:54Z",
5+
"published": "2026-08-20T03:32:54Z",
6+
"aliases": [
7+
"CVE-2026-75628"
8+
],
9+
"details": "Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter.\n\noauth2_login reads the return parameter from the initiation request, runs same_origin_path over it, and stores the survivor in the session flow record as the post-login redirect target. That check rejects a value that does not begin with a slash, one with a slash as its second byte, and one containing CR or LF. A backslash and a tab pass. The URL Standard treats a backslash as equivalent to a slash for special schemes, so `/\\evil.example` parses with the authority `evil.example`. It also strips ASCII tab before parsing, so a tab between two leading slashes leaves `//evil.example`.\n\nA crafted link to the application's own login route lands the victim on the attacker's site after a genuine authentication. The redirect carries no authorization code or access token.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75628"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://datatracker.ietf.org/doc/html/rfc9700#section-4.11.1"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://metacpan.org/release/LNATION/Punk-OAuth2-0.02/source/include/pox/pox_util.h#L94"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://metacpan.org/release/LNATION/Punk-OAuth2-0.03/changes"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://url.spec.whatwg.org/#concept-basic-url-parser"
32+
},
33+
{
34+
"type": "WEB",
35+
"url": "https://url.spec.whatwg.org/#relative-slash-state"
36+
},
37+
{
38+
"type": "WEB",
39+
"url": "http://www.openwall.com/lists/oss-security/2026/08/20/1"
40+
}
41+
],
42+
"database_specific": {
43+
"cwe_ids": [
44+
"CWE-601"
45+
],
46+
"severity": null,
47+
"github_reviewed": false,
48+
"github_reviewed_at": null,
49+
"nvd_published_at": "2026-08-20T01:16:53Z"
50+
}
51+
}
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-w9cf-gwfc-2v2x",
4+
"modified": "2026-08-20T03:32:54Z",
5+
"published": "2026-08-20T03:32:54Z",
6+
"aliases": [
7+
"CVE-2026-76785"
8+
],
9+
"details": "A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76785"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/amirsanni/Mini-Inventory-and-Sales-Management-System/issues/101"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/amirsanni/Mini-Inventory-and-Sales-Management-System"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/cve/CVE-2026-76785"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/submit/879829"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/393250"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://vuldb.com/vuln/393250/cti"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-74"
54+
],
55+
"severity": "LOW",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-08-20T01:16:54Z"
59+
}
60+
}

0 commit comments

Comments
 (0)