Skip to content

Commit 5c58439

Browse files
Sync EUVD catalog: Mon May 4 00:46:50 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 1b7a168 commit 5c58439

40 files changed

Lines changed: 2186 additions & 1 deletion
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"id": "EUVD-2026-26806",
3+
"enisaUuid": "e12a31f8-07a9-3b58-a464-5d2f3c29e827",
4+
"description": "Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence.\n\nStarlet incorrectly prioritizes \"Content-Length\" over \"Transfer-Encoding: chunked\" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence.\n\nAn attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.",
5+
"datePublished": "May 3, 2026, 12:57:31 AM",
6+
"dateUpdated": "May 3, 2026, 12:57:31 AM",
7+
"baseScore": 0.0,
8+
"references": "https://datatracker.ietf.org/doc/html/rfc7230#section-3.3.3\nhttps://github.com/kazuho/Starlet/commit/a7d5dfd1862aafa43e5eaca0fdb6acf4cc15b2d0.patch\n",
9+
"aliases": "CVE-2026-40561\n",
10+
"assigner": "CPANSec",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "c1ce9b7e-aebf-3fe5-a096-2e3f7b63365f",
15+
"product": {
16+
"name": "Starlet"
17+
},
18+
"product_version": "0 \u22640.31"
19+
}
20+
],
21+
"enisaIdVendor": [
22+
{
23+
"id": "deffc784-3bf8-38f6-8ba2-884d6612adf2",
24+
"vendor": {
25+
"name": "KAZUHO"
26+
}
27+
}
28+
]
29+
}
Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
{
2+
"id": "EUVD-2026-26807",
3+
"enisaUuid": "6f1c2861-ff51-3131-83c4-e889d8499843",
4+
"description": "A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin Upload. Performing a manipulation of the argument model results in unrestricted upload. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "May 3, 2026, 1:15:37 AM",
6+
"dateUpdated": "May 3, 2026, 1:15:37 AM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/360826\nhttps://vuldb.com/vuln/360826/cti\nhttps://vuldb.com/submit/800684\nhttps://fx4tqqfvdw4.feishu.cn/docx/EgMOdHyq6oyxhux5vpJcr5cgnAf?from=from_copylink\n",
11+
"aliases": "CVE-2026-7673\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "32025ff0-f713-34e4-aecc-ccbdc47abd4a",
17+
"product": {
18+
"name": "crmeb_java"
19+
},
20+
"product_version": "1.3.1"
21+
},
22+
{
23+
"id": "33be4ced-115b-3142-b43a-60b78d48673c",
24+
"product": {
25+
"name": "crmeb_java"
26+
},
27+
"product_version": "1.3.2"
28+
},
29+
{
30+
"id": "5f4fe1ef-feab-3291-9648-42e3b3916595",
31+
"product": {
32+
"name": "crmeb_java"
33+
},
34+
"product_version": "1.3.3"
35+
},
36+
{
37+
"id": "67c0bac7-3476-370c-8580-1cc1c55d9dce",
38+
"product": {
39+
"name": "crmeb_java"
40+
},
41+
"product_version": "1.3.0"
42+
},
43+
{
44+
"id": "eac5c1bd-714f-3c84-9ba7-d9cb46a3f5be",
45+
"product": {
46+
"name": "crmeb_java"
47+
},
48+
"product_version": "1.3.4"
49+
}
50+
],
51+
"enisaIdVendor": [
52+
{
53+
"id": "3df41afd-4209-3ff0-99a4-0087b172aef5",
54+
"vendor": {
55+
"name": "n/a"
56+
}
57+
}
58+
]
59+
}
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
{
2+
"id": "EUVD-2026-26808",
3+
"enisaUuid": "db206000-37ae-3cb2-9420-cb088e41e54f",
4+
"description": "A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_single_service of the component Web Management Interface. Executing a manipulation of the argument vpn_pptp_server/vpn_l2tp_server can lead to buffer overflow. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "May 3, 2026, 1:30:14 AM",
6+
"dateUpdated": "May 3, 2026, 1:30:14 AM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X",
10+
"references": "https://vuldb.com/vuln/360827\nhttps://vuldb.com/vuln/360827/cti\nhttps://vuldb.com/submit/800705\nhttps://vuldb.com/submit/800706\nhttps://github.com/hmKunlun/lbt-t300-hw1/blob/main/reselov_vpn_server%EF%BC%88vpn_pptp_server%EF%BC%89.md\n",
11+
"aliases": "CVE-2026-7674\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0dad6994-9144-33a3-ae27-2d9e383c3a16",
17+
"product": {
18+
"name": "LBT-T300-HW1"
19+
},
20+
"product_version": "1.2.6"
21+
},
22+
{
23+
"id": "25c9927d-435e-3529-8991-f58463cc460b",
24+
"product": {
25+
"name": "LBT-T300-HW1"
26+
},
27+
"product_version": "1.2.2"
28+
},
29+
{
30+
"id": "4d6846b0-110c-3afa-aa32-4bc34367d38d",
31+
"product": {
32+
"name": "LBT-T300-HW1"
33+
},
34+
"product_version": "1.2.0"
35+
},
36+
{
37+
"id": "536c5ff1-d324-3113-b0df-07b4eb3060bf",
38+
"product": {
39+
"name": "LBT-T300-HW1"
40+
},
41+
"product_version": "1.2.7"
42+
},
43+
{
44+
"id": "d4c6ac1e-c457-3811-bcf7-dfbec1b81038",
45+
"product": {
46+
"name": "LBT-T300-HW1"
47+
},
48+
"product_version": "1.2.3"
49+
},
50+
{
51+
"id": "d5a88497-f66c-3e15-a053-34f0988a11ce",
52+
"product": {
53+
"name": "LBT-T300-HW1"
54+
},
55+
"product_version": "1.2.1"
56+
},
57+
{
58+
"id": "db535771-4c48-374b-988f-0316fad9fda3",
59+
"product": {
60+
"name": "LBT-T300-HW1"
61+
},
62+
"product_version": "1.2.8"
63+
},
64+
{
65+
"id": "e7d3018a-0bcc-3d3e-89b9-8890d7f03097",
66+
"product": {
67+
"name": "LBT-T300-HW1"
68+
},
69+
"product_version": "1.2.4"
70+
},
71+
{
72+
"id": "fe05599e-9164-3aaa-9a3f-26d4d0e3d95a",
73+
"product": {
74+
"name": "LBT-T300-HW1"
75+
},
76+
"product_version": "1.2.5"
77+
}
78+
],
79+
"enisaIdVendor": [
80+
{
81+
"id": "a376cacc-36cd-357c-8703-7f484ae80156",
82+
"vendor": {
83+
"name": "Shenzhen Libituo Technology"
84+
}
85+
}
86+
]
87+
}
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
{
2+
"id": "EUVD-2026-26809",
3+
"enisaUuid": "152a0439-5989-3cc8-991a-1bed71fa74fa",
4+
"description": "A vulnerability has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. Impacted is the function start_lan of the file /apply.cgi. The manipulation of the argument Channel/ApCliSsid leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "May 3, 2026, 2:30:11 AM",
6+
"dateUpdated": "May 3, 2026, 2:30:11 AM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/360828\nhttps://vuldb.com/vuln/360828/cti\nhttps://vuldb.com/submit/800708\nhttps://vuldb.com/submit/800709\nhttps://github.com/hmKunlun/lbt-t300-hw1/blob/main/generate_conf_router(Channel).md\n",
11+
"aliases": "CVE-2026-7675\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "1c37e025-2842-333a-a851-2f4cf7a58075",
17+
"product": {
18+
"name": "LBT-T300-HW1"
19+
},
20+
"product_version": "1.2.2"
21+
},
22+
{
23+
"id": "625011cf-8973-3af9-ac4c-a818a177d953",
24+
"product": {
25+
"name": "LBT-T300-HW1"
26+
},
27+
"product_version": "1.2.4"
28+
},
29+
{
30+
"id": "6431b88d-9547-3345-9726-709738f5a9bc",
31+
"product": {
32+
"name": "LBT-T300-HW1"
33+
},
34+
"product_version": "1.2.5"
35+
},
36+
{
37+
"id": "736c2c52-b583-3e39-8949-693f94ae184d",
38+
"product": {
39+
"name": "LBT-T300-HW1"
40+
},
41+
"product_version": "1.2.6"
42+
},
43+
{
44+
"id": "7a432d4b-8055-3419-9e4d-714a5259cbca",
45+
"product": {
46+
"name": "LBT-T300-HW1"
47+
},
48+
"product_version": "1.2.3"
49+
},
50+
{
51+
"id": "9ba7c2d4-ac43-3ce3-bd34-bef505468653",
52+
"product": {
53+
"name": "LBT-T300-HW1"
54+
},
55+
"product_version": "1.2.1"
56+
},
57+
{
58+
"id": "b696edbe-0d99-3d6f-bafe-284a07fa3d1a",
59+
"product": {
60+
"name": "LBT-T300-HW1"
61+
},
62+
"product_version": "1.2.0"
63+
},
64+
{
65+
"id": "b72fe159-2a11-3292-8c79-b1098e546a42",
66+
"product": {
67+
"name": "LBT-T300-HW1"
68+
},
69+
"product_version": "1.2.7"
70+
},
71+
{
72+
"id": "fde3c292-f5dc-3ae3-9c96-b82743e80e2b",
73+
"product": {
74+
"name": "LBT-T300-HW1"
75+
},
76+
"product_version": "1.2.8"
77+
}
78+
],
79+
"enisaIdVendor": [
80+
{
81+
"id": "e736741c-f31e-3675-b1d5-ebd702e3edfb",
82+
"vendor": {
83+
"name": "Shenzhen Libituo Technology"
84+
}
85+
}
86+
]
87+
}
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
{
2+
"id": "EUVD-2026-26810",
3+
"enisaUuid": "6218df14-d352-3dcd-b825-bd8d8deffdbf",
4+
"description": "A vulnerability was found in kerwincui FastBee up to 1.2.1. The affected element is the function ToolController.download of the file springboot/fastbee-open-api/src/main/java/com/fastbee/data/controller/ToolController.java of the component Tool Download Endpoint. The manipulation of the argument fileName results in path traversal. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "May 3, 2026, 3:00:45 AM",
6+
"dateUpdated": "May 3, 2026, 3:00:45 AM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/360829\nhttps://vuldb.com/vuln/360829/cti\nhttps://vuldb.com/submit/800723\nhttps://fx4tqqfvdw4.feishu.cn/docx/Yv1gdAzFpoHCUUxDdKSculR4nKf?from=from_copylink\n",
11+
"aliases": "CVE-2026-7676\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "44d90d67-88d9-358c-82a7-9e73a5d3830e",
17+
"product": {
18+
"name": "FastBee"
19+
},
20+
"product_version": "1.2.1"
21+
},
22+
{
23+
"id": "f10c4737-590b-37bb-a0cc-b0f79f3eb517",
24+
"product": {
25+
"name": "FastBee"
26+
},
27+
"product_version": "1.2.0"
28+
}
29+
],
30+
"enisaIdVendor": [
31+
{
32+
"id": "4f62bfb4-817b-31e0-bdaa-106b35d66ae3",
33+
"vendor": {
34+
"name": "kerwincui"
35+
}
36+
}
37+
]
38+
}
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
{
2+
"id": "EUVD-2026-26811",
3+
"enisaUuid": "ca3e8f8a-6f42-369c-bedf-6c85ba365e68",
4+
"description": "A vulnerability was determined in kerwincui FastBee up to 1.2.1. The impacted element is the function Add of the file springboot/fastbee-admin/src/main/java/com/fastbee/web/controller/system/SysNoticeController.java of the component System Notice Handler. This manipulation of the argument noticeContent causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "May 3, 2026, 3:15:33 AM",
6+
"dateUpdated": "May 3, 2026, 3:15:33 AM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/360830\nhttps://vuldb.com/vuln/360830/cti\nhttps://vuldb.com/submit/800724\nhttps://fx4tqqfvdw4.feishu.cn/docx/Iu5Dd558UoS4uIxhH9YcgNsWnjc?from=from_copylink\n",
11+
"aliases": "CVE-2026-7677\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0b3c7313-a2ed-3b9d-a067-3b2db20f21ed",
17+
"product": {
18+
"name": "FastBee"
19+
},
20+
"product_version": "1.2.1"
21+
},
22+
{
23+
"id": "dcbfa902-8b1d-360f-a14b-c918bfd9351e",
24+
"product": {
25+
"name": "FastBee"
26+
},
27+
"product_version": "1.2.0"
28+
}
29+
],
30+
"enisaIdVendor": [
31+
{
32+
"id": "9eac67a2-86f9-3d60-8441-9618e32d8501",
33+
"vendor": {
34+
"name": "kerwincui"
35+
}
36+
}
37+
]
38+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2026-26813",
3+
"enisaUuid": "95d3327e-10bb-3867-adb2-fa0bf89dd513",
4+
"description": "A vulnerability was identified in YunaiV yudao-cloud up to 2026.01. This affects the function getDataBySQL of the file yudao-module-report-biz/src/main/java/io/github/ruoyi/report/service/impl/GoViewDataServiceImpl.java. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "May 3, 2026, 4:00:14 AM",
6+
"dateUpdated": "May 3, 2026, 4:00:14 AM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/360831\nhttps://vuldb.com/vuln/360831/cti\nhttps://vuldb.com/submit/800865\nhttps://github.com/9str0IL/CVE/issues/2\n",
11+
"aliases": "CVE-2026-7678\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0f97f477-7c16-3ad1-b432-944dba059b4b",
17+
"product": {
18+
"name": "yudao-cloud"
19+
},
20+
"product_version": "2026.01"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "1e3b430a-8ddb-3680-b142-62f3d18e37f0",
26+
"vendor": {
27+
"name": "YunaiV"
28+
}
29+
}
30+
]
31+
}

0 commit comments

Comments
 (0)