Skip to content

Commit 6833d28

Browse files
Sync EUVD catalog: Mon Jul 20 00:40:10 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 2c04f52 commit 6833d28

465 files changed

Lines changed: 67914 additions & 6 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/07/EUVD-2026-41859.json

Lines changed: 53 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,62 @@
33
"enisaUuid": "46c58010-d6d8-3652-90ff-1932609b9e8d",
44
"description": "A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.",
55
"datePublished": "Jul 6, 2026, 8:46:22 AM",
6-
"dateUpdated": "Jul 6, 2026, 8:46:22 AM",
6+
"dateUpdated": "Jul 19, 2026, 12:11:39 AM",
77
"baseScore": 7.7,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
10-
"references": "https://access.redhat.com/security/cve/CVE-2026-9165\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2480505\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2026:36207\nhttps://access.redhat.com/errata/RHSA-2026:36319\nhttps://access.redhat.com/errata/RHSA-2026:36625\nhttps://access.redhat.com/security/cve/CVE-2026-9165\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2480505\n",
1111
"aliases": "GHSA-fw53-q2vg-jr6g\nCVE-2026-9165\n",
1212
"assigner": "redhat",
13-
"epss": 0.0,
14-
"enisaIdProduct": [],
15-
"enisaIdVendor": []
13+
"epss": 0.32,
14+
"enisaIdProduct": [
15+
{
16+
"id": "1e9a61a0-94c7-34c6-b2a8-a07861ee6373",
17+
"product": {
18+
"name": "Red Hat Advanced Cluster Security for Kubernetes 4.10",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
22+
},
23+
"product_version": "patch: 1783357140"
24+
},
25+
{
26+
"id": "d1aaf961-3ab5-3ecf-80ef-844168b5cf07",
27+
"product": {
28+
"name": "Red Hat Advanced Cluster Security for Kubernetes 4.11",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
32+
},
33+
"product_version": "patch: 1783352589"
34+
},
35+
{
36+
"id": "e0e9ed1f-1686-3b7d-9d78-8eed65c1be5e",
37+
"product": {
38+
"name": "Red Hat Advanced Cluster Security 4.9",
39+
"vendor": {
40+
"name": "Red Hat"
41+
}
42+
},
43+
"product_version": "patch: 1783357116"
44+
},
45+
{
46+
"id": "ee0feb47-b219-3d4a-9c72-345dc31a4621",
47+
"product": {
48+
"name": "Red Hat Advanced Cluster Security for Kubernetes 4.9",
49+
"vendor": {
50+
"name": "Red Hat"
51+
}
52+
},
53+
"product_version": "patch: 1783357116"
54+
}
55+
],
56+
"enisaIdVendor": [
57+
{
58+
"id": "c550becc-8707-3400-a290-84f56b57238a",
59+
"vendor": {
60+
"name": "Red Hat"
61+
}
62+
}
63+
]
1664
}
Lines changed: 64 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,64 @@
1+
{
2+
"id": "EUVD-2026-45410",
3+
"enisaUuid": "d7a599b5-5839-3171-99fb-afee39ab1447",
4+
"description": "A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used.",
5+
"datePublished": "Jul 19, 2026, 12:00:12 AM",
6+
"dateUpdated": "Jul 19, 2026, 12:00:12 AM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/380015\nhttps://vuldb.com/vuln/380015/cti\nhttps://vuldb.com/cve/CVE-2026-16199\nhttps://vuldb.com/submit/857621\nhttps://github.com/nextlevelbuilder/goclaw/issues/1215\nhttps://github.com/nextlevelbuilder/goclaw/issues/1215#issuecomment-4760153807\nhttps://github.com/nextlevelbuilder/goclaw/\n",
11+
"aliases": "GHSA-gch8-7366-6m32\nCVE-2026-16199\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "1db5d637-1324-3585-818d-400314955efd",
17+
"product": {
18+
"name": "GoClaw",
19+
"vendor": {
20+
"name": "nextlevelbuilder"
21+
}
22+
},
23+
"product_version": "3.13.3-beta.3"
24+
},
25+
{
26+
"id": "5b4b75a2-d7af-3352-9451-0824da1bb529",
27+
"product": {
28+
"name": "GoClaw",
29+
"vendor": {
30+
"name": "nextlevelbuilder"
31+
}
32+
},
33+
"product_version": "3.13.3-beta.1"
34+
},
35+
{
36+
"id": "6a780336-4566-3639-8dc9-1c11647f69d1",
37+
"product": {
38+
"name": "GoClaw",
39+
"vendor": {
40+
"name": "nextlevelbuilder"
41+
}
42+
},
43+
"product_version": "3.13.3-beta.0"
44+
},
45+
{
46+
"id": "e3179a5c-0caa-3da2-b7a0-e712feaa395a",
47+
"product": {
48+
"name": "GoClaw",
49+
"vendor": {
50+
"name": "nextlevelbuilder"
51+
}
52+
},
53+
"product_version": "3.13.3-beta.2"
54+
}
55+
],
56+
"enisaIdVendor": [
57+
{
58+
"id": "38047883-4bd2-38ff-824f-8ad7dacc0a17",
59+
"vendor": {
60+
"name": "nextlevelbuilder"
61+
}
62+
}
63+
]
64+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2026-45411",
3+
"enisaUuid": "ef65803a-b2fe-3c7b-b562-2f71e0b5200f",
4+
"description": "A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The manipulation leads to incorrect authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
5+
"datePublished": "Jul 19, 2026, 12:15:10 AM",
6+
"dateUpdated": "Jul 19, 2026, 12:15:10 AM",
7+
"baseScore": 6.9,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/380016\nhttps://vuldb.com/vuln/380016/cti\nhttps://vuldb.com/cve/CVE-2026-16200\nhttps://vuldb.com/submit/857622\nhttps://github.com/zevorn/rt-claw/issues/133\nhttps://github.com/zevorn/rt-claw/\n",
11+
"aliases": "CVE-2026-16200\nGHSA-9869-2292-xxj6\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "359b289a-68dc-300e-8f1b-f7c09306e7ee",
17+
"product": {
18+
"name": "rt-claw",
19+
"vendor": {
20+
"name": "zevorn"
21+
}
22+
},
23+
"product_version": "0.1"
24+
},
25+
{
26+
"id": "65581286-42ac-341c-91fd-02e33f54e0c9",
27+
"product": {
28+
"name": "rt-claw",
29+
"vendor": {
30+
"name": "zevorn"
31+
}
32+
},
33+
"product_version": "0.2.0"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "09b7987d-839d-3124-b8af-2e16accc4175",
39+
"vendor": {
40+
"name": "zevorn"
41+
}
42+
}
43+
]
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2026-45412",
3+
"enisaUuid": "8c40f17f-db0a-3b6d-8d97-dcb01c6cb640",
4+
"description": "A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation results in information disclosure. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.",
5+
"datePublished": "Jul 19, 2026, 12:45:10 AM",
6+
"dateUpdated": "Jul 19, 2026, 12:45:10 AM",
7+
"baseScore": 6.9,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/380017\nhttps://vuldb.com/vuln/380017/cti\nhttps://vuldb.com/cve/CVE-2026-16201\nhttps://vuldb.com/submit/857623\nhttps://github.com/zevorn/rt-claw/issues/136\nhttps://github.com/zevorn/rt-claw/\n",
11+
"aliases": "GHSA-qc6r-fr26-j2gm\nCVE-2026-16201\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "2cf41681-dc91-32b6-84dd-8888a81a639b",
17+
"product": {
18+
"name": "rt-claw",
19+
"vendor": {
20+
"name": "zevorn"
21+
}
22+
},
23+
"product_version": "0.1"
24+
},
25+
{
26+
"id": "3ca86213-1e85-3850-a5f1-825b077aa648",
27+
"product": {
28+
"name": "rt-claw",
29+
"vendor": {
30+
"name": "zevorn"
31+
}
32+
},
33+
"product_version": "0.2.0"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "96a1fc4c-35b9-38da-97c3-34f4313eb099",
39+
"vendor": {
40+
"name": "zevorn"
41+
}
42+
}
43+
]
44+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-45413",
3+
"enisaUuid": "500291e6-f164-31f4-9084-61756c620122",
4+
"description": "A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.",
5+
"datePublished": "Jul 19, 2026, 1:15:10 AM",
6+
"dateUpdated": "Jul 19, 2026, 1:15:10 AM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/380018\nhttps://vuldb.com/vuln/380018/cti\nhttps://vuldb.com/cve/CVE-2026-16202\nhttps://vuldb.com/submit/857765\nhttps://github.com/AlbaDove/cve/issues/9\nhttps://www.sourcecodester.com/\n",
11+
"aliases": "CVE-2026-16202\nGHSA-grp8-2555-3cmp\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "eddef177-460e-3029-b0e3-8cdbaf6c01d6",
17+
"product": {
18+
"name": "Class and Exam Timetabling System",
19+
"vendor": {
20+
"name": "SourceCodester"
21+
}
22+
},
23+
"product_version": "1.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "85cd9ed9-26b8-35da-9a97-1c6c781db451",
29+
"vendor": {
30+
"name": "SourceCodester"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-45414",
3+
"enisaUuid": "7806433d-7908-3f5c-9fad-42449e87459c",
4+
"description": "A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such manipulation of the argument course leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used.",
5+
"datePublished": "Jul 19, 2026, 1:30:09 AM",
6+
"dateUpdated": "Jul 19, 2026, 1:30:09 AM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/380019\nhttps://vuldb.com/vuln/380019/cti\nhttps://vuldb.com/cve/CVE-2026-16203\nhttps://vuldb.com/submit/857766\nhttps://github.com/AlbaDove/cve/issues/8\nhttps://www.sourcecodester.com/\n",
11+
"aliases": "GHSA-5frv-67vm-973m\nCVE-2026-16203\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "f90e0902-1ec0-38b5-8384-5a089dccfb4c",
17+
"product": {
18+
"name": "Class and Exam Timetabling System",
19+
"vendor": {
20+
"name": "SourceCodester"
21+
}
22+
},
23+
"product_version": "1.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "619cfb3d-9135-3298-96d9-8af3c56e78a3",
29+
"vendor": {
30+
"name": "SourceCodester"
31+
}
32+
}
33+
]
34+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2026-45415",
3+
"enisaUuid": "953bec1f-0b0e-3416-b423-a384ef5c7532",
4+
"description": "A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. Performing a manipulation results in code injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
5+
"datePublished": "Jul 19, 2026, 1:45:11 AM",
6+
"dateUpdated": "Jul 19, 2026, 1:45:11 AM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/380020\nhttps://vuldb.com/vuln/380020/cti\nhttps://vuldb.com/cve/CVE-2026-16204\nhttps://vuldb.com/submit/857784\nhttps://github.com/zevorn/rt-claw/issues/138\nhttps://github.com/zevorn/rt-claw/\n",
11+
"aliases": "CVE-2026-16204\nGHSA-xr38-w5rc-h3q4\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "031c6743-757d-347e-9fa2-bef2d6cb7f36",
17+
"product": {
18+
"name": "rt-claw",
19+
"vendor": {
20+
"name": "zevorn"
21+
}
22+
},
23+
"product_version": "0.1"
24+
},
25+
{
26+
"id": "ea6b7477-ff45-3c6f-8145-b85b1a007adf",
27+
"product": {
28+
"name": "rt-claw",
29+
"vendor": {
30+
"name": "zevorn"
31+
}
32+
},
33+
"product_version": "0.2.0"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "db831b42-9258-385e-acca-6e4f2b7fd61d",
39+
"vendor": {
40+
"name": "zevorn"
41+
}
42+
}
43+
]
44+
}

0 commit comments

Comments
 (0)