Skip to content

Commit 22f1570

Browse files
Sync EUVD catalog: Mon Jul 6 00:46:40 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent cfdca7d commit 22f1570

118 files changed

Lines changed: 4678 additions & 102 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/05/EUVD-2023-28274.json

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,17 +3,22 @@
33
"enisaUuid": "6a10ec1c-9d0c-3f94-903e-5fe352182a59",
44
"description": "Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.",
55
"datePublished": "May 18, 2026, 12:00:00 AM",
6-
"dateUpdated": "May 18, 2026, 5:04:04 PM",
7-
"baseScore": 0.0,
8-
"references": "http://airgate.com\nhttp://novus.com\nhttps://github.com/sql3t0/cve-disclosures/blob/main/00_-_CVE-2023-24215.md\n",
6+
"dateUpdated": "Jul 5, 2026, 1:35:23 AM",
7+
"baseScore": 9.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
10+
"references": "http://novus.com\nhttps://github.com/sql3t0/cve-disclosures/blob/main/00_-_CVE-2023-24215.md\n",
911
"aliases": "CVE-2023-24215\nGHSA-fhqm-w73x-978p\n",
1012
"assigner": "mitre",
11-
"epss": 0.0,
13+
"epss": 0.28,
1214
"enisaIdProduct": [
1315
{
1416
"id": "10a54eeb-b5c1-3604-af62-8df4f058712f",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
1924
}

advisories/2026/05/EUVD-2025-209923.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2025-209923",
33
"enisaUuid": "1320e6dd-2b3f-3e87-b8bd-f20e77392b70",
44
"description": "Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via the image parameter",
5-
"datePublished": "May 26, 2026, 1:30:17 PM",
6-
"dateUpdated": "May 26, 2026, 1:30:17 PM",
5+
"datePublished": "May 22, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 5, 2026, 1:35:28 AM",
77
"baseScore": 7.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
10-
"references": "http://follett.com\nhttps://medium.com/@jaredutahusa/cve-2025-45145-unauthenticated-local-file-inclusion-in-fsc-destiny-40a3f11b3a4d\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-45145\n",
10+
"references": "https://medium.com/@jaredutahusa/cve-2025-45145-unauthenticated-local-file-inclusion-in-fsc-destiny-40a3f11b3a4d\n",
1111
"aliases": "GHSA-99w5-3688-qwj6\nCVE-2025-45145\n",
1212
"assigner": "mitre",
13-
"epss": 0.63,
13+
"epss": 0.74,
1414
"enisaIdProduct": [
1515
{
1616
"id": "0f094de3-d1b0-3b1c-8b96-2a0072ea31e8",

advisories/2026/05/EUVD-2026-28391.json

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,23 @@
22
"id": "EUVD-2026-28391",
33
"enisaUuid": "d3194c84-5dd3-30e4-9d30-cf08bb2b5e63",
44
"description": "A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE.",
5-
"datePublished": "May 7, 2026, 6:30:40 PM",
6-
"dateUpdated": "May 7, 2026, 6:30:40 PM",
7-
"baseScore": 0.0,
8-
"references": "http://codeastro.com\nhttps://github.com/raneishajustin/CVE/tree/main/CVE-2026-36387\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-36387\n",
5+
"datePublished": "May 7, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 5, 2026, 1:34:48 AM",
7+
"baseScore": 6.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
10+
"references": "https://github.com/raneishajustin/CVE/tree/main/CVE-2026-36387\n",
911
"aliases": "CVE-2026-36387\nGHSA-rj73-qp5q-ppqx\n",
1012
"assigner": "mitre",
11-
"epss": 0.0,
13+
"epss": 0.27,
1214
"enisaIdProduct": [
1315
{
1416
"id": "35ffe84d-9466-3181-993f-f31fe474884d",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
1924
}

advisories/2026/05/EUVD-2026-28392.json

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,20 +2,23 @@
22
"id": "EUVD-2026-28392",
33
"enisaUuid": "d2ff9fb3-3a40-384c-bf05-0b6850d5bd8f",
44
"description": "A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored in the application and later rendered in the doctor s interface.",
5-
"datePublished": "May 7, 2026, 6:30:40 PM",
6-
"dateUpdated": "May 7, 2026, 6:30:40 PM",
5+
"datePublished": "May 7, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 5, 2026, 1:34:52 AM",
77
"baseScore": 5.4,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
10-
"references": "http://phpgurukal.com\nhttps://github.com/raneishajustin/CVE/tree/main/CVE-2026-36388\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-36388\n",
10+
"references": "https://github.com/raneishajustin/CVE/tree/main/CVE-2026-36388\n",
1111
"aliases": "GHSA-6f5m-3x87-fcxh\nCVE-2026-36388\n",
1212
"assigner": "mitre",
13-
"epss": 0.0,
13+
"epss": 0.14,
1414
"enisaIdProduct": [
1515
{
1616
"id": "d4687a78-eef0-3d21-9ad9-2ffdb9890e06",
1717
"product": {
18-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1922
},
2023
"product_version": "n/a"
2124
}

advisories/2026/05/EUVD-2026-29111.json

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,23 @@
22
"id": "EUVD-2026-29111",
33
"enisaUuid": "cec7d3c6-5a96-3045-ab88-fd34a6d64eb7",
44
"description": "Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function",
5-
"datePublished": "May 11, 2026, 6:31:45 PM",
6-
"dateUpdated": "May 11, 2026, 6:31:45 PM",
7-
"baseScore": 0.0,
8-
"references": "http://iotgateway.com\nhttp://iotgateway.net/\nhttps://github.com/iioter/iotgateway/issues/59\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-36906\n",
5+
"datePublished": "May 11, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 5, 2026, 1:35:11 AM",
7+
"baseScore": 6.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
10+
"references": "http://iotgateway.net/\nhttps://github.com/iioter/iotgateway/issues/59\n",
911
"aliases": "GHSA-5m68-j8g4-rv9f\nCVE-2026-36906\n",
1012
"assigner": "mitre",
11-
"epss": 0.0,
13+
"epss": 0.29,
1214
"enisaIdProduct": [
1315
{
1416
"id": "24f98bf4-ed3a-3039-9f3d-a68867f0657f",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
1924
}

advisories/2026/05/EUVD-2026-29203.json

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,23 @@
22
"id": "EUVD-2026-29203",
33
"enisaUuid": "f90ff1e4-35c1-3e5d-8cef-186d26f833d6",
44
"description": "EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient input validation, the attacker is able to execute arbitrary system commands on the device.",
5-
"datePublished": "May 11, 2026, 9:31:35 PM",
6-
"dateUpdated": "May 11, 2026, 9:31:35 PM",
7-
"baseScore": 0.0,
8-
"references": "http://edimax.com\nhttps://github.com/theShinigami/CVE-Disclosures/tree/main/CVE-2026-36734\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-36734\n",
5+
"datePublished": "May 11, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 5, 2026, 1:35:05 AM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
10+
"references": "https://github.com/theShinigami/CVE-Disclosures/tree/main/CVE-2026-36734\n",
911
"aliases": "GHSA-c9c6-xfr6-q42w\nCVE-2026-36734\n",
1012
"assigner": "mitre",
11-
"epss": 0.0,
13+
"epss": 1.02,
1214
"enisaIdProduct": [
1315
{
1416
"id": "4ac1824f-ab9a-36d3-adc1-e5f6369391df",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
1924
}

advisories/2026/05/EUVD-2026-29960.json

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,23 @@
22
"id": "EUVD-2026-29960",
33
"enisaUuid": "e8f5ffae-63e6-343b-88f0-8af91eac5570",
44
"description": "A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file operation functions (fopen/ifstream/ofstream) for file reading and writing. An attacker can exploit this vulnerability by constructing a malicious path to read arbitrary readable files.",
5-
"datePublished": "May 13, 2026, 6:30:54 PM",
6-
"dateUpdated": "May 13, 2026, 6:30:54 PM",
7-
"baseScore": 0.0,
8-
"references": "http://openplc.com\nhttps://github.com/unicorn-hyh/CVE-2026-31156\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-31156\n",
5+
"datePublished": "May 13, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 5, 2026, 1:35:15 AM",
7+
"baseScore": 6.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
10+
"references": "https://github.com/unicorn-hyh/CVE-2026-31156\n",
911
"aliases": "CVE-2026-31156\nGHSA-p6vg-5mm7-744x\n",
1012
"assigner": "mitre",
11-
"epss": 0.0,
13+
"epss": 0.41,
1214
"enisaIdProduct": [
1315
{
1416
"id": "7772980b-1d80-3946-9053-d2edd1b3fe5a",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
1924
}

advisories/2026/05/EUVD-2026-31464.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2026-31464",
33
"enisaUuid": "40ea822c-6255-3e0f-bf25-c21ad320dbff",
44
"description": "An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components",
5-
"datePublished": "May 26, 2026, 1:30:19 PM",
6-
"dateUpdated": "May 26, 2026, 1:30:19 PM",
5+
"datePublished": "May 22, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 5, 2026, 1:34:06 AM",
77
"baseScore": 7.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
10-
"references": "http://clipbucket.com\nhttps://medium.com/@arpit03sharma2003/cve-2026-37470-clickjacking-vulnerability-in-clipbucket-v5-leads-to-credential-theft-and-8415def7804a\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-37470\n",
10+
"references": "https://medium.com/@arpit03sharma2003/cve-2026-37470-clickjacking-vulnerability-in-clipbucket-v5-leads-to-credential-theft-and-8415def7804a\n",
1111
"aliases": "CVE-2026-37470\nGHSA-4367-8h95-cxcx\n",
1212
"assigner": "mitre",
13-
"epss": 0.05,
13+
"epss": 0.33,
1414
"enisaIdProduct": [
1515
{
1616
"id": "c1c79efc-82d0-3dd2-ac76-c5e21ad94226",

advisories/2026/05/EUVD-2026-31472.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2026-31472",
33
"enisaUuid": "e069e6ef-cab6-3d50-959b-09ad9843e76a",
44
"description": "Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the chat message functionality",
5-
"datePublished": "May 26, 2026, 1:30:19 PM",
6-
"dateUpdated": "May 26, 2026, 1:30:19 PM",
5+
"datePublished": "May 22, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 5, 2026, 1:34:28 AM",
77
"baseScore": 7.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
10-
"references": "http://easy.com\nhttps://github.com/NullByte8080/CVE-2026-36228\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-36228\n",
10+
"references": "https://github.com/NullByte8080/CVE-2026-36228\n",
1111
"aliases": "GHSA-jh5j-c5cw-c6g9\nCVE-2026-36228\n",
1212
"assigner": "mitre",
13-
"epss": 0.18,
13+
"epss": 0.51,
1414
"enisaIdProduct": [
1515
{
1616
"id": "36e44f61-68a4-3c2e-894b-f649df8eb267",

advisories/2026/05/EUVD-2026-31473.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2026-31473",
33
"enisaUuid": "e870a4ab-0e4c-3b82-b9a9-1a84f5164852",
44
"description": "Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the UserName parameter",
5-
"datePublished": "May 26, 2026, 1:30:19 PM",
6-
"dateUpdated": "May 26, 2026, 1:30:19 PM",
5+
"datePublished": "May 22, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 5, 2026, 1:34:24 AM",
77
"baseScore": 6.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
10-
"references": "http://easy.com\nhttps://github.com/NullByte8080/CVE-2026-36227\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-36227\n",
10+
"references": "https://github.com/NullByte8080/CVE-2026-36227\n",
1111
"aliases": "CVE-2026-36227\nGHSA-jxfv-852c-jjfw\n",
1212
"assigner": "mitre",
13-
"epss": 0.19,
13+
"epss": 0.95,
1414
"enisaIdProduct": [
1515
{
1616
"id": "6d105136-2739-3bf0-b94e-0f37d5010c7b",

0 commit comments

Comments
 (0)