Skip to content

Commit 1b758e4

Browse files
Sync EUVD catalog: Tue Jul 14 00:35:00 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent c332685 commit 1b758e4

325 files changed

Lines changed: 13556 additions & 1 deletion

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
{
2+
"id": "EUVD-2024-24347",
3+
"enisaUuid": "f8da9e0c-8741-3d6e-a755-a204efcca57d",
4+
"description": "GeoNode: Stored XSS to full account takeover",
5+
"datePublished": "Jul 13, 2026, 4:44:53 PM",
6+
"dateUpdated": "Jul 13, 2026, 4:44:54 PM",
7+
"baseScore": 6.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
10+
"references": "https://github.com/GeoNode/geonode/security/advisories/GHSA-rwcv-whm8-fmxm\nhttps://github.com/GeoNode/geonode/commit/e53bdeff331f4b577918927d60477d4b50cca02f\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-27091\nhttps://github.com/pypa/advisory-database/tree/main/vulns/geonode/PYSEC-2024-320.yaml\n",
11+
"aliases": "CVE-2024-27091\nGHSA-rwcv-whm8-fmxm\n",
12+
"assigner": "GitHub_M",
13+
"epss": 0.38,
14+
"enisaIdProduct": [
15+
{
16+
"id": "4ac77ec4-233d-3df1-8ab3-1156b7f4a348",
17+
"product": {
18+
"name": "geonode",
19+
"vendor": {
20+
"name": "GeoNode"
21+
}
22+
},
23+
"product_version": "3.2.0, < 4.2.3"
24+
},
25+
{
26+
"id": "66ac0670-e394-36ed-940c-76f56d3c9f7b",
27+
"product": {
28+
"name": "geonode",
29+
"vendor": {
30+
"name": "GeoNode"
31+
}
32+
}
33+
}
34+
],
35+
"enisaIdVendor": [
36+
{
37+
"id": "5d5ad314-d59e-38b4-a4c5-d66a4127cfe2",
38+
"vendor": {
39+
"name": "GeoNode"
40+
}
41+
}
42+
]
43+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-43256",
3+
"enisaUuid": "403e879c-8d04-3122-a9fc-386116d80bfe",
4+
"description": "A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path. The attack must be carried out locally. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "Jul 13, 2026, 12:00:10 AM",
6+
"dateUpdated": "Jul 13, 2026, 12:00:10 AM",
7+
"baseScore": 7.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/377844\nhttps://vuldb.com/vuln/377844/cti\nhttps://vuldb.com/cve/CVE-2026-15515\nhttps://vuldb.com/submit/848643\nhttps://github.com/subsubsub1231/qmukiller\n",
11+
"aliases": "GHSA-6pvh-5mc9-hm57\nCVE-2026-15515\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "c806b864-0bd3-3166-8875-2edd1789d856",
17+
"product": {
18+
"name": "PC Manager",
19+
"vendor": {
20+
"name": "Lenovo"
21+
}
22+
},
23+
"product_version": "18.1.30242.301"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "053ff406-fae9-30c0-b51c-02db10b9205a",
29+
"vendor": {
30+
"name": "Tencent"
31+
}
32+
}
33+
]
34+
}
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
{
2+
"id": "EUVD-2026-43257",
3+
"enisaUuid": "90ff851e-5b1f-3ed0-949c-6ab7f1e41bf0",
4+
"description": "Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers.\n\nThis issue affects .",
5+
"datePublished": "Jul 13, 2026, 12:11:59 AM",
6+
"dateUpdated": "Jul 13, 2026, 12:11:59 AM",
7+
"baseScore": 5.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H",
10+
"references": "https://github.com/Samsung/rlottie/pull/595\n",
11+
"aliases": "GHSA-h37q-3gh3-x72p\nCVE-2026-15551\n",
12+
"assigner": "samsung.tv_appliance",
13+
"epss": 0.0,
14+
"enisaIdProduct": [],
15+
"enisaIdVendor": []
16+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-43258",
3+
"enisaUuid": "1e66bad3-1b04-3126-9905-b1501afc0472",
4+
"description": "A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit is now public and may be used. Upgrading to version 2022.1000.3025 is recommended to address this issue. Upgrading the affected component is recommended.",
5+
"datePublished": "Jul 13, 2026, 12:15:08 AM",
6+
"dateUpdated": "Jul 13, 2026, 12:15:08 AM",
7+
"baseScore": 6.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/377845\nhttps://vuldb.com/vuln/377845/cti\nhttps://vuldb.com/cve/CVE-2026-15516\nhttps://vuldb.com/submit/848741\nhttps://github.com/trustbigcat/CVE/\nhttps://github.com/magicblack/maccms10/releases?page=3#release-v2022.1000.3025\n",
11+
"aliases": "GHSA-r7c2-xcmm-m4pr\nCVE-2026-15516\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "d620413f-7086-3519-abc4-39489cbc3cde",
17+
"product": {
18+
"name": "MacCMS Pro",
19+
"vendor": {
20+
"name": "n/a"
21+
}
22+
},
23+
"product_version": "2022.1000.3005"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "eaef2ead-f0a8-3d0b-92ef-4f8cbd0f94ca",
29+
"vendor": {
30+
"name": "n/a"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-43259",
3+
"enisaUuid": "72011f26-6b3f-3bfe-87b2-07e778aa2afb",
4+
"description": "A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx. This manipulation of the argument httpOID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "Jul 13, 2026, 12:30:08 AM",
6+
"dateUpdated": "Jul 13, 2026, 12:30:08 AM",
7+
"baseScore": 6.9,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/377846\nhttps://vuldb.com/vuln/377846/cti\nhttps://vuldb.com/cve/CVE-2026-15517\nhttps://vuldb.com/submit/849470\nhttps://github.com/weini587/CVE/issues/1\n",
11+
"aliases": "CVE-2026-15517\nGHSA-g9x4-g2rg-r435\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "b31a8ea7-7c08-3348-b3e8-8c13c30e6905",
17+
"product": {
18+
"name": "OA",
19+
"vendor": {
20+
"name": "Jinher"
21+
}
22+
},
23+
"product_version": "1.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "eedb4658-69ae-33e2-8e34-febc3262cffb",
29+
"vendor": {
30+
"name": "Jinher"
31+
}
32+
}
33+
]
34+
}
Lines changed: 94 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,94 @@
1+
{
2+
"id": "EUVD-2026-43260",
3+
"enisaUuid": "c4eebef0-2cfa-37ae-9527-9560fcba5ad6",
4+
"description": "A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. Such manipulation of the argument qqfilename leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "Jul 13, 2026, 12:45:08 AM",
6+
"dateUpdated": "Jul 13, 2026, 12:45:08 AM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/377847\nhttps://vuldb.com/vuln/377847/cti\nhttps://vuldb.com/cve/CVE-2026-15518\nhttps://vuldb.com/submit/849572\nhttps://bytium.com/insights/authenticated-arbitrary-file-upload-to-rce-in-twill-cms\n",
11+
"aliases": "GHSA-q9gx-wp22-jh5r\nCVE-2026-15518\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0c8fa45c-5523-3a7c-a035-14eab9035ed4",
17+
"product": {
18+
"name": "Twill CMS",
19+
"vendor": {
20+
"name": "AREA 17"
21+
}
22+
},
23+
"product_version": "3.2"
24+
},
25+
{
26+
"id": "62b18da7-a007-3228-8292-003e595e77e7",
27+
"product": {
28+
"name": "Twill CMS",
29+
"vendor": {
30+
"name": "AREA 17"
31+
}
32+
},
33+
"product_version": "3.4"
34+
},
35+
{
36+
"id": "8318546b-daef-36a7-8679-8991d2d5d59d",
37+
"product": {
38+
"name": "Twill CMS",
39+
"vendor": {
40+
"name": "AREA 17"
41+
}
42+
},
43+
"product_version": "3.5"
44+
},
45+
{
46+
"id": "921dac99-b0f1-35d7-a9ac-83c60ff79203",
47+
"product": {
48+
"name": "Twill CMS",
49+
"vendor": {
50+
"name": "AREA 17"
51+
}
52+
},
53+
"product_version": "3.3"
54+
},
55+
{
56+
"id": "923eb5b9-37d1-3671-a845-a35d3ee7652d",
57+
"product": {
58+
"name": "Twill CMS",
59+
"vendor": {
60+
"name": "AREA 17"
61+
}
62+
},
63+
"product_version": "3.0"
64+
},
65+
{
66+
"id": "efa6ece6-445a-3ef9-b30a-9f4ab4c4c17a",
67+
"product": {
68+
"name": "Twill CMS",
69+
"vendor": {
70+
"name": "AREA 17"
71+
}
72+
},
73+
"product_version": "3.1"
74+
},
75+
{
76+
"id": "feb97a99-05f6-3b6c-979c-34750971597a",
77+
"product": {
78+
"name": "Twill CMS",
79+
"vendor": {
80+
"name": "AREA 17"
81+
}
82+
},
83+
"product_version": "3.6.0"
84+
}
85+
],
86+
"enisaIdVendor": [
87+
{
88+
"id": "34d7bee4-cca5-399b-bc16-577edd749f18",
89+
"vendor": {
90+
"name": "AREA 17"
91+
}
92+
}
93+
]
94+
}

0 commit comments

Comments
 (0)