Skip to content

Commit fd72a90

Browse files
Advisory Database Sync
1 parent 819fcf1 commit fd72a90

87 files changed

Lines changed: 1862 additions & 203 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/unreviewed/2024/01/GHSA-fh6j-mgh8-7prh/GHSA-fh6j-mgh8-7prh.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-fh6j-mgh8-7prh",
4-
"modified": "2026-07-22T18:31:44Z",
4+
"modified": "2026-08-03T18:30:28Z",
55
"published": "2024-01-25T21:32:14Z",
66
"aliases": [
77
"CVE-2023-52355"
@@ -55,6 +55,10 @@
5555
"type": "WEB",
5656
"url": "https://access.redhat.com/errata/RHSA-2026:43537"
5757
},
58+
{
59+
"type": "WEB",
60+
"url": "https://access.redhat.com/errata/RHSA-2026:49671"
61+
},
5862
{
5963
"type": "WEB",
6064
"url": "https://access.redhat.com/security/cve/CVE-2023-52355"

advisories/unreviewed/2026/06/GHSA-cg4c-j43f-qcg7/GHSA-cg4c-j43f-qcg7.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-cg4c-j43f-qcg7",
4-
"modified": "2026-08-03T09:32:35Z",
4+
"modified": "2026-08-03T18:30:28Z",
55
"published": "2026-06-29T18:31:54Z",
66
"aliases": [
77
"CVE-2026-12912"
@@ -39,6 +39,10 @@
3939
"type": "WEB",
4040
"url": "https://access.redhat.com/errata/RHSA-2026:47184"
4141
},
42+
{
43+
"type": "WEB",
44+
"url": "https://access.redhat.com/errata/RHSA-2026:49671"
45+
},
4246
{
4347
"type": "WEB",
4448
"url": "https://access.redhat.com/security/cve/CVE-2026-12912"

advisories/unreviewed/2026/06/GHSA-crh6-pvh7-v7wf/GHSA-crh6-pvh7-v7wf.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-crh6-pvh7-v7wf",
4-
"modified": "2026-06-15T00:31:49Z",
4+
"modified": "2026-08-03T18:30:28Z",
55
"published": "2026-06-15T00:31:49Z",
66
"aliases": [
77
"CVE-2026-12188"
@@ -23,6 +23,10 @@
2323
"type": "ADVISORY",
2424
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12188"
2525
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/heylaika/vuln-research-program/blob/main/2026/CVE-2026-12188%20-%20grit42%20-%20SQL%20Injection%20in%20CSV%20Export%20Endpoint/README.md"
29+
},
2630
{
2731
"type": "WEB",
2832
"url": "https://github.com/natanmorette-thoropass/thoropass-vuln-research-program/blob/main/2026/SQL%20Injection%20in%20grit42%20CSV%20Export%20Endpoint/README.md"

advisories/unreviewed/2026/07/GHSA-5p7v-jxww-9qjm/GHSA-5p7v-jxww-9qjm.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,8 @@
2626
],
2727
"database_specific": {
2828
"cwe_ids": [
29-
"CWE-306"
29+
"CWE-306",
30+
"CWE-862"
3031
],
3132
"severity": "MODERATE",
3233
"github_reviewed": false,

advisories/unreviewed/2026/07/GHSA-6p99-w6f4-qcvq/GHSA-6p99-w6f4-qcvq.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-6p99-w6f4-qcvq",
4-
"modified": "2026-07-31T15:32:42Z",
4+
"modified": "2026-08-03T18:30:29Z",
55
"published": "2026-07-23T06:32:13Z",
66
"aliases": [
77
"CVE-2026-64600"
@@ -66,6 +66,10 @@
6666
{
6767
"type": "WEB",
6868
"url": "http://www.openwall.com/lists/oss-security/2026/07/31/3"
69+
},
70+
{
71+
"type": "WEB",
72+
"url": "http://www.openwall.com/lists/oss-security/2026/08/03/4"
6973
}
7074
],
7175
"database_specific": {

advisories/unreviewed/2026/07/GHSA-6vmp-jgfm-6r3v/GHSA-6vmp-jgfm-6r3v.json

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-6vmp-jgfm-6r3v",
4-
"modified": "2026-07-30T03:31:12Z",
4+
"modified": "2026-08-03T18:30:31Z",
55
"published": "2026-07-30T03:31:12Z",
66
"aliases": [
77
"CVE-2026-17755"
88
],
99
"details": "Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -24,8 +29,10 @@
2429
}
2530
],
2631
"database_specific": {
27-
"cwe_ids": [],
28-
"severity": null,
32+
"cwe_ids": [
33+
"CWE-451"
34+
],
35+
"severity": "MODERATE",
2936
"github_reviewed": false,
3037
"github_reviewed_at": null,
3138
"nvd_published_at": "2026-07-30T01:16:38Z"

advisories/unreviewed/2026/07/GHSA-765r-wfrw-h7w2/GHSA-765r-wfrw-h7w2.json

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-765r-wfrw-h7w2",
4-
"modified": "2026-07-30T03:31:13Z",
4+
"modified": "2026-08-03T18:30:31Z",
55
"published": "2026-07-30T03:31:13Z",
66
"aliases": [
77
"CVE-2026-17787"
88
],
99
"details": "Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -24,8 +29,10 @@
2429
}
2530
],
2631
"database_specific": {
27-
"cwe_ids": [],
28-
"severity": null,
32+
"cwe_ids": [
33+
"CWE-346"
34+
],
35+
"severity": "MODERATE",
2936
"github_reviewed": false,
3037
"github_reviewed_at": null,
3138
"nvd_published_at": "2026-07-30T01:16:42Z"

advisories/unreviewed/2026/07/GHSA-7763-rg25-m3fc/GHSA-7763-rg25-m3fc.json

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-7763-rg25-m3fc",
4-
"modified": "2026-07-30T21:31:50Z",
4+
"modified": "2026-08-03T18:30:36Z",
55
"published": "2026-07-30T21:31:50Z",
66
"aliases": [
77
"CVE-2025-69931"
88
],
99
"details": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -20,8 +25,10 @@
2025
}
2126
],
2227
"database_specific": {
23-
"cwe_ids": [],
24-
"severity": null,
28+
"cwe_ids": [
29+
"CWE-89"
30+
],
31+
"severity": "CRITICAL",
2532
"github_reviewed": false,
2633
"github_reviewed_at": null,
2734
"nvd_published_at": "2026-07-30T21:16:52Z"

advisories/unreviewed/2026/07/GHSA-8h3p-4mcm-phwx/GHSA-8h3p-4mcm-phwx.json

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-8h3p-4mcm-phwx",
4-
"modified": "2026-07-31T18:32:17Z",
4+
"modified": "2026-08-03T18:30:36Z",
55
"published": "2026-07-31T18:32:17Z",
66
"aliases": [
77
"CVE-2026-16504"
88
],
99
"details": "Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password (\"zulip\"), and DISABLE_HTTPS=True.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -20,8 +25,10 @@
2025
}
2126
],
2227
"database_specific": {
23-
"cwe_ids": [],
24-
"severity": null,
28+
"cwe_ids": [
29+
"CWE-321"
30+
],
31+
"severity": "CRITICAL",
2532
"github_reviewed": false,
2633
"github_reviewed_at": null,
2734
"nvd_published_at": "2026-07-31T16:16:58Z"

advisories/unreviewed/2026/07/GHSA-8mxp-hf23-8hp4/GHSA-8mxp-hf23-8hp4.json

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-8mxp-hf23-8hp4",
4-
"modified": "2026-07-31T21:31:59Z",
4+
"modified": "2026-08-03T18:30:37Z",
55
"published": "2026-07-31T21:31:59Z",
66
"aliases": [
77
"CVE-2026-51785"
88
],
99
"details": "An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -32,8 +37,10 @@
3237
}
3338
],
3439
"database_specific": {
35-
"cwe_ids": [],
36-
"severity": null,
40+
"cwe_ids": [
41+
"CWE-94"
42+
],
43+
"severity": "CRITICAL",
3744
"github_reviewed": false,
3845
"github_reviewed_at": null,
3946
"nvd_published_at": "2026-07-31T21:17:31Z"

0 commit comments

Comments
 (0)