Skip to content

Commit 2e65db8

Browse files
Sync EUVD catalog: Tue May 26 00:52:01 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 1918208 commit 2e65db8

190 files changed

Lines changed: 6809 additions & 11 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/03/EUVD-2026-14301.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
"id": "EUVD-2026-14301",
33
"enisaUuid": "4c9f0b5d-1ad6-3c51-87bc-010739354a44",
44
"description": "A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic signature. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The real existence of this vulnerability is still doubted at the moment. The patch is identified as af996b5ec27ab79bae3882071b9d6acf16044549. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a patch for the affected product. However, at the moment there is no proof that this flaw might have any real-world impact.",
5-
"datePublished": "Mar 22, 2026, 3:31:28 PM",
6-
"dateUpdated": "Mar 22, 2026, 3:31:28 PM",
5+
"datePublished": "Mar 22, 2026, 12:15:07 PM",
6+
"dateUpdated": "May 25, 2026, 1:42:39 AM",
77
"baseScore": 6.3,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
10-
"references": "https://vuldb.com/?id.352429\nhttps://vuldb.com/?ctiid.352429\nhttps://vuldb.com/?submit.775576\nhttps://github.com/py-thok/putty-ed25519-malleability-s-plus-l\nhttps://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/eddsa-overlarge-s.html\nhttps://github.com/py-thok/putty-ed25519-malleability-s-plus-l/blob/main/poc.py\nhttps://git.tartarus.org/?p=simon/putty.git;a=commitdiff;h=af996b5ec27ab79bae3882071b9d6acf16044549\nhttps://www.rfc-editor.org/rfc/rfc8032#section-8.4\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-4115\n",
10+
"references": "https://vuldb.com/?id.352429\nhttps://vuldb.com/?ctiid.352429\nhttps://vuldb.com/?submit.775576\nhttps://github.com/py-thok/putty-ed25519-malleability-s-plus-l\nhttps://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/eddsa-overlarge-s.html\nhttps://github.com/py-thok/putty-ed25519-malleability-s-plus-l/blob/main/poc.py\nhttps://git.tartarus.org/?p=simon/putty.git;a=commitdiff;h=af996b5ec27ab79bae3882071b9d6acf16044549\nhttps://www.rfc-editor.org/rfc/rfc8032#section-8.4\n",
1111
"aliases": "GHSA-p96h-94q2-fh5v\nCVE-2026-4115\n",
1212
"assigner": "VulDB",
1313
"epss": 0.01,
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2018-21881",
3+
"enisaUuid": "2b084bf3-df52-3271-8073-38d57e87453b",
4+
"description": "Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered.",
5+
"datePublished": "May 25, 2026, 2:15:06 PM",
6+
"dateUpdated": "May 25, 2026, 2:15:06 PM",
7+
"baseScore": 8.6,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45072\nhttps://www.splinterware.com\nhttps://www.vulncheck.com/advisories/splinterware-system-scheduler-pro-privilege-escalation\n",
11+
"aliases": "CVE-2018-25359\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "174482c1-ff91-345c-ba89-3011fd5df2b4",
17+
"product": {
18+
"name": "Splinterware System Scheduler Pro"
19+
},
20+
"product_version": "5.12"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "863f82b7-55fa-34f4-b47a-850d69be93eb",
26+
"vendor": {
27+
"name": "Splinterware"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2018-21882",
3+
"enisaUuid": "d7f77243-8630-3a1b-a0ea-c82220c221c9",
4+
"description": "Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information including usernames, passwords, and database credentials.",
5+
"datePublished": "May 25, 2026, 2:15:09 PM",
6+
"dateUpdated": "May 25, 2026, 2:15:09 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45230\nhttps://github.com/Fyffe/PHP-Twitter-Clone/\nhttps://www.vulncheck.com/advisories/twitter-clone-1-sql-injection-via-follow-php\n",
11+
"aliases": "CVE-2018-25362\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "da4e015a-e905-3d1e-8748-2aef83eacdcb",
17+
"product": {
18+
"name": "PHP-Twitter-Clone"
19+
},
20+
"product_version": "1.0"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "8f275b86-fb9a-342e-9655-b857af0f2bc8",
26+
"vendor": {
27+
"name": "Fyffe"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2018-21883",
3+
"enisaUuid": "00b436c8-64c6-3db2-8b3e-b4cdda4ff05e",
4+
"description": "Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and access all stored data, chats, images, and files without knowing the original passcode.",
5+
"datePublished": "May 25, 2026, 2:15:08 PM",
6+
"dateUpdated": "May 25, 2026, 2:15:08 PM",
7+
"baseScore": 7.0,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45171\nhttps://soroush-app.ir\nhttp://54.36.43.176/SoroushSetup0.17.0.exe\nhttps://www.vulncheck.com/advisories/soroush-im-desktop-app-authentication-bypass-via-database-injection\n",
11+
"aliases": "CVE-2018-25361\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "ca52e90b-e6a2-3635-a5f6-b42575d9bc78",
17+
"product": {
18+
"name": "Soroush Messenger"
19+
},
20+
"product_version": "0.17.0"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "4342a759-015b-316e-8ea7-9c78a1ce4cf1",
26+
"vendor": {
27+
"name": "Soroush"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2018-21884",
3+
"enisaUuid": "4c784079-bbac-359e-8b21-813c727bb056",
4+
"description": "AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious ping.txt file with shellcode and jump instructions that overwrite the SEH handler pointer to achieve code execution when the file contents are pasted into the application.",
5+
"datePublished": "May 25, 2026, 2:15:07 PM",
6+
"dateUpdated": "May 25, 2026, 2:15:07 PM",
7+
"baseScore": 8.6,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45151\nhttp://agatasoft.com/\nhttps://www.vulncheck.com/advisories/agatasoft-auto-pingmaster-buffer-overflow-seh\n",
11+
"aliases": "CVE-2018-25360\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "087d71a1-c230-3ca5-87a5-9d39bd88bc9d",
17+
"product": {
18+
"name": "Auto PingMaster"
19+
},
20+
"product_version": "1.5"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "638dd1ef-e786-35c7-9cae-f26a2dc02b12",
26+
"vendor": {
27+
"name": "Agatasoft"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2018-21885",
3+
"enisaUuid": "efec0309-db90-3a41-8d6a-5658fff936c9",
4+
"description": "PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use path traversal sequences ../../../../../../../../../../../../etc/passwd to access sensitive system files outside the intended directory.",
5+
"datePublished": "May 25, 2026, 2:15:11 PM",
6+
"dateUpdated": "May 25, 2026, 2:15:11 PM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45248\nhttp://www.softpedia.com/get/System/File-Management/Pc-Viewer.shtml\nhttps://www.vulncheck.com/advisories/pcviewer-vt1000-directory-traversal-via-get-request\n",
11+
"aliases": "CVE-2018-25365\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "feeb1d4b-723e-3173-a85e-3a4a7c3a2775",
17+
"product": {
18+
"name": "PCViewer"
19+
},
20+
"product_version": "vt1000"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "60befe55-7cf1-31a0-92a2-4dbb08bed5c1",
26+
"vendor": {
27+
"name": "Softpedia"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2018-21886",
3+
"enisaUuid": "8f38708c-9c42-3c91-910a-cfb5b5ab2001",
4+
"description": "Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the name parameter. Attackers can submit crafted payloads to the search.php endpoint to extract database information including usernames, credentials, and system data using error-based and union-based SQL injection techniques.",
5+
"datePublished": "May 25, 2026, 2:15:11 PM",
6+
"dateUpdated": "May 25, 2026, 2:15:11 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45247\nhttps://github.com/Fyffe/PHP-Twitter-Clone/\nhttps://www.vulncheck.com/advisories/twitter-clone-1-sql-injection-via-search-php\n",
11+
"aliases": "CVE-2018-25364\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "e7a58136-5805-325f-a320-7329a6892aed",
17+
"product": {
18+
"name": "PHP-Twitter-Clone"
19+
},
20+
"product_version": "1.0"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "ca9779f3-6e6f-3623-ac77-41639005e74a",
26+
"vendor": {
27+
"name": "Fyffe"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2018-21887",
3+
"enisaUuid": "af485815-08cd-35cf-8bc6-052828634b4d",
4+
"description": "Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms targeting tweetdel.php with tweet IDs and automatically submit them to delete arbitrary posts from authenticated user sessions.",
5+
"datePublished": "May 25, 2026, 2:15:10 PM",
6+
"dateUpdated": "May 25, 2026, 2:15:10 PM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L",
10+
"references": "https://www.exploit-db.com/exploits/45232\nhttps://github.com/Fyffe/PHP-Twitter-Clone/\nhttps://www.vulncheck.com/advisories/twitter-clone-1-cross-site-request-forgery-via-tweetdel-php\n",
11+
"aliases": "CVE-2018-25363\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "d688d6e3-8b2d-3b07-ad82-3c9c748cff08",
17+
"product": {
18+
"name": "PHP-Twitter-Clone"
19+
},
20+
"product_version": "1.0"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "1669ca4f-fa65-3cf1-aa09-1e0ab88125df",
26+
"vendor": {
27+
"name": "Fyffe"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2018-21888",
3+
"enisaUuid": "c5d24247-4295-3d96-aa6e-b0730f1a7e38",
4+
"description": "NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom browser pod addition interface.",
5+
"datePublished": "May 25, 2026, 2:15:13 PM",
6+
"dateUpdated": "May 25, 2026, 2:15:13 PM",
7+
"baseScore": 6.9,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45281\nhttps://github.com/nasa/OpenVSP\nhttps://www.vulncheck.com/advisories/nasa-openvsp-denial-of-service-via-buffer-overflow\n",
11+
"aliases": "CVE-2018-25367\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "cbcd732b-0037-3b11-9c87-317edb8dc93a",
17+
"product": {
18+
"name": "openVSP"
19+
},
20+
"product_version": "3.16.1"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "352c6aa2-566f-35d4-90ec-f3a2db93c769",
26+
"vendor": {
27+
"name": "NASA"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2018-21889",
3+
"enisaUuid": "cb61ba14-50d5-346d-8741-5a6b41fa134a",
4+
"description": "CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and launched.",
5+
"datePublished": "May 25, 2026, 2:15:12 PM",
6+
"dateUpdated": "May 25, 2026, 2:15:12 PM",
7+
"baseScore": 8.6,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/45259\nhttp://installer.globalscape.com/pub/cuteftp/archive/english/cuteftp50.exe\nhttps://www.vulncheck.com/advisories/cuteftp-xp-buffer-overflow-via-site-manager-label-field\n",
11+
"aliases": "CVE-2018-25366\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0f073714-95e3-328c-a583-bfa9184ff777",
17+
"product": {
18+
"name": "CuteFTP"
19+
},
20+
"product_version": "5.0.4"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "711802ea-9995-3e2a-8786-3221e6b03d00",
26+
"vendor": {
27+
"name": "globalscape"
28+
}
29+
}
30+
]
31+
}

0 commit comments

Comments
 (0)