Skip to content

Commit 6fab7ea

Browse files
Sync EUVD catalog: Fri Jul 17 00:38:43 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent aee42c1 commit 6fab7ea

281 files changed

Lines changed: 11298 additions & 58 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2021-34854",
3+
"enisaUuid": "01649a77-e63e-3b53-b9c3-df73207db374",
4+
"description": "An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).",
5+
"datePublished": "Jul 16, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 16, 2026, 6:24:38 PM",
7+
"baseScore": 8.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
10+
"references": "https://svn.dd-wrt.com/changeset/45724\nhttps://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/\nhttps://securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html\nhttps://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/\nhttps://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo\n",
11+
"aliases": "GHSA-qx3v-2jx6-8m2c\nCVE-2021-27137\n",
12+
"assigner": "mitre",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "ca9e266e-93d7-3461-88e2-091df160d4db",
17+
"product": {
18+
"name": "DD-WRT",
19+
"vendor": {
20+
"name": "embeDD GmbH"
21+
}
22+
},
23+
"product_version": "0 <45724"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "e7deb0df-d269-345e-96ae-f1d274050a4e",
29+
"vendor": {
30+
"name": "DD-WRT"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2023-60600",
3+
"enisaUuid": "f2f94ec4-aedc-3150-ab18-9bde26b05a50",
4+
"description": "An unauthenticated remote attacker is able to perform remote code execution\u00a0due to incorrectly sanitized user input in the SetParameter command.",
5+
"datePublished": "Jul 16, 2026, 10:11:11 AM",
6+
"dateUpdated": "Jul 16, 2026, 3:11:14 PM",
7+
"baseScore": 9.8,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
10+
"references": "https://claroty.com/team82/disclosure-dashboard/cve-2023-49900\n",
11+
"aliases": "CVE-2023-49900\nGHSA-3g8c-pp6x-x9gw\n",
12+
"assigner": "CERTVDE",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "66edca4c-2952-3aaf-b786-b709682c812b",
17+
"product": {
18+
"name": "MA-T6",
19+
"vendor": {
20+
"name": "X-Rite"
21+
}
22+
},
23+
"product_version": "0 <v2.33"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "87e726cd-e8fe-3ad4-9634-afd112db626c",
29+
"vendor": {
30+
"name": "X-Rite"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2023-60601",
3+
"enisaUuid": "be4ecec4-af08-3e76-a316-f2d9556a5b9d",
4+
"description": "An unauthenticated remote attacker can\u00a0execute any command on the affected device due to not correctly verifying the origin of a communication channel.",
5+
"datePublished": "Jul 16, 2026, 10:11:32 AM",
6+
"dateUpdated": "Jul 16, 2026, 10:11:32 AM",
7+
"baseScore": 9.8,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
10+
"references": "https://claroty.com/team82/disclosure-dashboard/cve-2023-49899\n",
11+
"aliases": "CVE-2023-49899\nGHSA-587v-8x94-p9vx\n",
12+
"assigner": "CERTVDE",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "19586a70-5ed2-3bea-827e-b5d5ffb0adcc",
17+
"product": {
18+
"name": "MA-T6",
19+
"vendor": {
20+
"name": "X-Rite"
21+
}
22+
},
23+
"product_version": "0 <v2.33"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "ee11c0a8-6c0b-3f75-a171-996db47a4305",
29+
"vendor": {
30+
"name": "X-Rite"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55652",
3+
"enisaUuid": "d1ae814f-ab72-3efa-97ca-2d661fb684a8",
4+
"description": "stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity.",
5+
"datePublished": "Jul 16, 2026, 12:23:14 PM",
6+
"dateUpdated": "Jul 16, 2026, 12:23:14 PM",
7+
"baseScore": 6.9,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-f26h-rqjq-qqjq\nhttps://github.com/stoatchat/stoatchat/commit/eda36436a862bcab92f7ac2cf1c2dd88c41e52a4\nhttps://www.vulncheck.com/advisories/stoatchat-before-unrestricted-account-creation\n",
11+
"aliases": "CVE-2024-58360\nGHSA-x85w-r7mc-2chj\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0c214cf1-ac9c-336d-97a4-862ba401f8da",
17+
"product": {
18+
"name": "stoatchat",
19+
"vendor": {
20+
"name": "stoatchat"
21+
}
22+
},
23+
"product_version": "0 <0.7.8"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "5bf5490e-626b-3f14-88d6-5851f56c3fe7",
29+
"vendor": {
30+
"name": "stoatchat"
31+
}
32+
}
33+
]
34+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2025-210474",
3+
"enisaUuid": "50f6c571-7fc5-300d-ad69-0ee4c40d78f5",
4+
"description": "An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.",
5+
"datePublished": "Jul 16, 2026, 12:31:33 AM",
6+
"dateUpdated": "Jul 16, 2026, 12:31:33 AM",
7+
"baseScore": 0.0,
8+
"references": "https://github.com/assafelovic/gpt-researcher\nhttps://www.ox.security/blog/gpt-researcher-remote-code-execution\nhttps://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-65720\n",
9+
"aliases": "CVE-2025-65720\nGHSA-8j86-h8gg-797p\n",
10+
"assigner": "mitre",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "1cf530c8-739c-31d3-8f34-504257f25b79",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "da19ddc2-7e58-37d7-927c-222bac52132e",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2025-210475",
3+
"enisaUuid": "9ca3ff44-14f0-357c-9ff5-594a1d22c60a",
4+
"description": "stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.",
5+
"datePublished": "Jul 16, 2026, 12:19:14 PM",
6+
"dateUpdated": "Jul 16, 2026, 12:59:14 PM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-h7h6-7pxm-mc66\nhttps://github.com/stoatchat/stoatchat/commit/5f84daa9dba34c103cd83a2ee1f5e5ba900bfe94\nhttps://www.vulncheck.com/advisories/stoatchat-before-20250210-1-unrestricted-message-history-fetch\n",
11+
"aliases": "CVE-2025-71377\nGHSA-6j45-2pq3-r728\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "8f89f0a6-da3c-39ae-9da0-64a6f553e74b",
17+
"product": {
18+
"name": "stoatchat",
19+
"vendor": {
20+
"name": "stoatchat"
21+
}
22+
},
23+
"product_version": "0 <20250210-1 (0.8.2)"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "1f8a7c71-fbb9-308e-a8c4-bab700d7867a",
29+
"vendor": {
30+
"name": "stoatchat"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2025-210476",
3+
"enisaUuid": "1ad77a62-c3cb-339a-b7c1-1787721e9d31",
4+
"description": "stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead of ManageWebhooks. Using a retrieved token, an attacker can send arbitrary messages to the channel, bypassing channel permissions and impersonating a bot or webhook. Fixed in 20250210-1 (0.8.2).",
5+
"datePublished": "Jul 16, 2026, 12:19:15 PM",
6+
"dateUpdated": "Jul 16, 2026, 3:10:58 PM",
7+
"baseScore": 7.6,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-8684-rvfj-v3jq\nhttps://github.com/stoatchat/stoatchat/commit/e3723d647effb81ea3d3919d848faf64dbe89829\nhttps://www.vulncheck.com/advisories/stoatchat-20241213-1-webhook-token-disclosure-via-read-permissions\n",
11+
"aliases": "GHSA-9hv3-3cv6-jrx3\nCVE-2025-71388\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "80d4267b-1719-36fb-8f0b-fa14758d0a07",
17+
"product": {
18+
"name": "stoatchat",
19+
"vendor": {
20+
"name": "stoatchat"
21+
}
22+
},
23+
"product_version": "20241213-1 <20250210-1"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "2e09eee0-a3be-3827-842e-765be2a3209a",
29+
"vendor": {
30+
"name": "stoatchat"
31+
}
32+
}
33+
]
34+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2025-210477",
3+
"enisaUuid": "f78eb6f9-e7f9-3a6b-8556-2b011ea59d2e",
4+
"description": "LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.",
5+
"datePublished": "Jul 16, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 16, 2026, 3:35:52 PM",
7+
"baseScore": 0.0,
8+
"references": "https://www.logicaldoc.com/\nhttps://github.com/netero1010/Vulnerability-Disclosure/blob/main/CVE-2025-45868/README.md\n",
9+
"aliases": "CVE-2025-45868\nGHSA-952c-x8w4-pg22\n",
10+
"assigner": "mitre",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "eb9ad420-7047-3060-953a-43a1913b7b35",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "8924ac68-8072-3fef-b573-7b898a2ac218",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2025-210478",
3+
"enisaUuid": "952e570f-6be6-305e-a9c3-420aa457a6b3",
4+
"description": "LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories.",
5+
"datePublished": "Jul 16, 2026, 12:00:00 AM",
6+
"dateUpdated": "Jul 16, 2026, 4:26:51 PM",
7+
"baseScore": 0.0,
8+
"references": "https://www.logicaldoc.com/\nhttps://github.com/netero1010/Vulnerability-Disclosure/blob/main/CVE-2025-45870/README.md\n",
9+
"aliases": "GHSA-c3rf-pmgq-wq29\nCVE-2025-45870\n",
10+
"assigner": "mitre",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "e877074a-b1ff-32ef-894c-59096c3e1a19",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "b1fc03e8-8c16-3cfb-a756-8625fc8b42ab",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}

advisories/2026/07/EUVD-2026-44736.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "bfc7e64f-ea24-30de-87e1-e2d976c56fea",
44
"description": "In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the `edit_local_apps` and `install_apps` capabilities could cause a legitimate app installation to write files outside the intended app directory, into `$SPLUNK_HOME/etc/` and its subdirectories.<br><br>The vulnerability is caused by a path traversal in the app installation workflow, which does not restrict the installation path to the intended app directory.",
55
"datePublished": "Jul 15, 2026, 5:18:13 PM",
6-
"dateUpdated": "Jul 15, 2026, 6:10:35 PM",
6+
"dateUpdated": "Jul 16, 2026, 3:55:53 AM",
77
"baseScore": 7.2,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",

0 commit comments

Comments
 (0)