Skip to content

Commit aee42c1

Browse files
Sync EUVD catalog: Thu Jul 16 00:36:18 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent eb5b8eb commit aee42c1

712 files changed

Lines changed: 17723 additions & 865 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/05/EUVD-2018-21878.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2018-21878",
33
"enisaUuid": "d03729c6-da97-32da-90b2-7b229e401c39",
44
"description": "Audiograbber 1.83 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling mechanisms. Attackers can craft malicious input in the Interpret or Album fields that triggers a buffer overflow, overwriting SEH pointers and executing injected shellcode with application privileges.",
5-
"datePublished": "May 26, 2026, 1:30:27 PM",
6-
"dateUpdated": "May 26, 2026, 1:30:27 PM",
5+
"datePublished": "May 23, 2026, 6:30:54 PM",
6+
"dateUpdated": "Jul 15, 2026, 1:23:36 AM",
77
"baseScore": 8.6,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/44903\nhttps://www.audiograbber.org/\nhttps://www.vulncheck.com/advisories/audiograbber-local-buffer-overflow-via-seh\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-25355\n",
10+
"references": "https://www.exploit-db.com/exploits/44903\nhttps://www.audiograbber.org/\nhttps://www.vulncheck.com/advisories/audiograbber-local-buffer-overflow-via-seh\n",
1111
"aliases": "GHSA-fvmg-8g58-84fj\nCVE-2018-25355\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.01,
13+
"epss": 0.16,
1414
"enisaIdProduct": [
1515
{
1616
"id": "9566d232-dad2-384c-8371-d99ff132fc09",

advisories/2026/05/EUVD-2018-21880.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2018-21880",
33
"enisaUuid": "ece5afec-672d-3423-9e3d-1a753d141bad",
44
"description": "D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST requests. Attackers can send requests to /my_cgi.cgi with table_name values like admin_user, wireless_settings, and wireless_security to extract administrative credentials and wireless network keys in clear text.",
5-
"datePublished": "May 26, 2026, 1:30:27 PM",
6-
"dateUpdated": "May 26, 2026, 1:30:27 PM",
5+
"datePublished": "May 23, 2026, 6:30:57 PM",
6+
"dateUpdated": "Jul 15, 2026, 1:23:37 AM",
77
"baseScore": 8.7,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/45002\nhttp://ca.dlink.com/\nhttps://www.packetlabs.net\nhttp://support.dlink.ca/ProductInfo.aspx?m=DIR-601\nhttps://www.vulncheck.com/advisories/d-link-dir601-2-02na-credential-disclosure-via-my-cgi-cgi\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-25358\n",
10+
"references": "https://www.exploit-db.com/exploits/45002\nhttp://ca.dlink.com/\nhttps://www.packetlabs.net\nhttp://support.dlink.ca/ProductInfo.aspx?m=DIR-601\nhttps://www.vulncheck.com/advisories/d-link-dir601-2-02na-credential-disclosure-via-my-cgi-cgi\n",
1111
"aliases": "CVE-2018-25358\nGHSA-6w5x-hr69-xx7v\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.09,
13+
"epss": 0.58,
1414
"enisaIdProduct": [
1515
{
1616
"id": "5865e03e-4ff1-3ce5-9c5e-7064f1b7b74f",

advisories/2026/05/EUVD-2018-21893.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "b9a3dacb-0959-3dca-9b8c-c91404d696bf",
44
"description": "Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious HTML forms targeting roles_function.php with parameters like rol_assign_roles, rol_approve_users, and rol_edit_user set to 1 to escalate privileges without authentication.",
55
"datePublished": "May 25, 2026, 2:15:15 PM",
6-
"dateUpdated": "May 26, 2026, 3:00:45 PM",
6+
"dateUpdated": "Jul 15, 2026, 1:23:38 AM",
77
"baseScore": 6.9,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L",
1010
"references": "https://www.exploit-db.com/exploits/45322\nhttps://www.admidio.org/\nhttps://sourceforge.net/projects/admidio/files/Admidio/3.3.x/admidio-3.3.5.zip/download\nhttps://www.vulncheck.com/advisories/admidio-cross-site-request-forgery-via-roles-function-php\n",
1111
"aliases": "GHSA-76g9-r7wc-v9q8\nCVE-2018-25370\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.19,
1414
"enisaIdProduct": [
1515
{
1616
"id": "9b9f37d8-a23f-3dfa-90fc-6c28836bf069",

advisories/2026/05/EUVD-2018-21915.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "3e08bc8d-d262-3b09-81ab-4d6616f59313",
44
"description": "Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. Attackers can send GET requests to navigate_download.php with path traversal payloads ../../../cfg/globals.php to access sensitive configuration files and system files outside the intended directory.",
55
"datePublished": "May 29, 2026, 2:46:35 PM",
6-
"dateUpdated": "May 29, 2026, 5:23:40 PM",
6+
"dateUpdated": "Jul 15, 2026, 1:23:38 AM",
77
"baseScore": 7.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
1010
"references": "https://www.exploit-db.com/exploits/45615\nhttps://www.navigatecms.com/\nhttp://master.dl.sourceforge.net/project/navigatecms/releases/navigate-2.8.5r1355.zip\nhttps://www.vulncheck.com/advisories/navigate-cms-path-traversal-via-navigate-download-php\n",
1111
"aliases": "CVE-2018-25393\nGHSA-rj56-vp9h-3frj\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.57,
1414
"enisaIdProduct": [
1515
{
1616
"id": "7811ac7a-3238-3e5a-a409-28edd2962f91",

advisories/2026/05/EUVD-2018-21927.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "4c9ed5d4-78a7-37d6-bc00-9583a17ba6e4",
44
"description": "eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters to extract sensitive database information including usernames, database names, and version details.",
55
"datePublished": "May 30, 2026, 2:55:12 PM",
6-
"dateUpdated": "May 30, 2026, 2:55:12 PM",
6+
"dateUpdated": "Jul 15, 2026, 1:23:39 AM",
77
"baseScore": 8.8,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
1010
"references": "https://www.exploit-db.com/exploits/45654\nhttp://www.endonesia.org/\nhttps://sourceforge.net/projects/endonesia/files/latest/download\nhttps://www.vulncheck.com/advisories/endonesia-portal-sql-injection-via-mod-php\n",
1111
"aliases": "GHSA-7976-cwgg-p8cx\nCVE-2018-25405\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.27,
1414
"enisaIdProduct": [
1515
{
1616
"id": "8a499a27-8d9f-36ba-9747-0f9668c9ca87",

advisories/2026/05/EUVD-2018-21928.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "82f71f94-29ef-347e-a5c7-d6b9cf68f881",
44
"description": "eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database credentials, usernames, and version information.",
55
"datePublished": "May 30, 2026, 2:55:14 PM",
6-
"dateUpdated": "Jun 2, 2026, 1:59:08 AM",
6+
"dateUpdated": "Jul 15, 2026, 1:23:40 AM",
77
"baseScore": 8.8,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
1010
"references": "https://www.exploit-db.com/exploits/45654\nhttp://www.endonesia.org/\nhttps://sourceforge.net/projects/endonesia/files/latest/download\nhttps://www.vulncheck.com/advisories/endonesia-portal-sql-injection-via-mod-php-2\n",
1111
"aliases": "GHSA-pj9c-49f9-pw37\nCVE-2018-25406\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.07,
13+
"epss": 0.27,
1414
"enisaIdProduct": [
1515
{
1616
"id": "c88f0314-a648-3770-b701-eb5c1b654bea",

advisories/2026/05/EUVD-2018-21929.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "0b8fbbfd-7204-3410-9489-3cea81f2679d",
44
"description": "eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database information including usernames, database names, and version details.",
55
"datePublished": "May 30, 2026, 2:55:14 PM",
6-
"dateUpdated": "May 30, 2026, 2:55:14 PM",
6+
"dateUpdated": "Jul 15, 2026, 1:23:40 AM",
77
"baseScore": 8.8,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
1010
"references": "https://www.exploit-db.com/exploits/45654\nhttp://www.endonesia.org/\nhttps://sourceforge.net/projects/endonesia/files/latest/download\nhttps://www.vulncheck.com/advisories/endonesia-portal-sql-injection-via-mod-php-3\n",
1111
"aliases": "CVE-2018-25407\nGHSA-34x7-vqxj-ppp4\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.27,
1414
"enisaIdProduct": [
1515
{
1616
"id": "5846a951-9e4d-39ed-85ea-8eb486025bd9",

advisories/2026/05/EUVD-2018-21943.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "b8d16678-2053-37ea-be76-b887a2ec2e8f",
44
"description": "Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send GET requests to modules/backup/actions.php with op=getfile and traverse directories using ../ sequences to access sensitive system files.",
55
"datePublished": "May 30, 2026, 2:55:25 PM",
6-
"dateUpdated": "May 30, 2026, 2:55:25 PM",
6+
"dateUpdated": "Jul 15, 2026, 1:23:41 AM",
77
"baseScore": 7.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
1010
"references": "https://www.exploit-db.com/exploits/45693\nhttp://www.openstamanager.com/\nhttps://sourceforge.net/projects/openstamanager/files/latest/download\nhttps://www.vulncheck.com/advisories/open-sta-manager-arbitrary-file-download-via-path-traversal\n",
1111
"aliases": "GHSA-g8r5-7mhq-74mj\nCVE-2018-25421\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.33,
1414
"enisaIdProduct": [
1515
{
1616
"id": "73481a07-4367-39e5-b30c-fbbce854bbec",

advisories/2026/05/EUVD-2023-60576.json

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,26 +3,32 @@
33
"enisaUuid": "d583e7fd-0840-31e7-b4fb-8274992fd4c9",
44
"description": "Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when values contain an odd number of characters. Attackers can obtain signatures on truncated or misinterpreted message values to authorize unintended blockchain transactions, such as asset transfers at incorrect amounts.",
55
"datePublished": "May 19, 2026, 9:55:51 PM",
6-
"dateUpdated": "May 20, 2026, 1:20:14 PM",
6+
"dateUpdated": "Jul 15, 2026, 1:25:01 AM",
77
"baseScore": 6.9,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
1010
"references": "https://donjon.ledger.com/lsb/020/\nhttps://www.vulncheck.com/advisories/ledger-live-hw-app-eth-eip-712-message-parsing-integer-truncation\n",
1111
"aliases": "CVE-2023-7345\nGHSA-m3cf-54jv-7mmj\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.26,
1414
"enisaIdProduct": [
1515
{
1616
"id": "a6e6b01c-14bb-302d-b99a-d93f3a0c61e4",
1717
"product": {
18-
"name": "Ledger Live"
18+
"name": "Ledger Live",
19+
"vendor": {
20+
"name": "Ledger"
21+
}
1922
},
2023
"product_version": "0 <2.70.0"
2124
},
2225
{
2326
"id": "b53c107c-88a9-32ba-8a86-5b6e1aadfa52",
2427
"product": {
25-
"name": "ledgerhq/hw-app-eth"
28+
"name": "ledgerhq/hw-app-eth",
29+
"vendor": {
30+
"name": "Ledger"
31+
}
2632
},
2733
"product_version": "0 <6.34.7"
2834
}

advisories/2026/05/EUVD-2025-209897.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "7fc752cb-7df4-3ddd-bec9-8f87610eba22",
44
"description": "An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].",
55
"datePublished": "May 19, 2026, 12:00:00 AM",
6-
"dateUpdated": "Jun 30, 2026, 2:43:50 AM",
6+
"dateUpdated": "Jul 15, 2026, 1:26:10 AM",
77
"baseScore": 7.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
1010
"references": "https://github.com/modelscope/modelscope/issues/1331\nhttps://github.com/modelscope/modelscope/pull/1333\nhttps://github.com/JIRUWOZHI/vulnerability-disclosure/blob/main/CVE-2025-51427/CVE_2025_51427.md\n",
11-
"aliases": "GHSA-fhhq-h4hg-549x\nCVE-2025-51427\n",
11+
"aliases": "GHSA-fhhq-h4hg-549x\nPYSEC-2026-2663\nCVE-2025-51427\n",
1212
"assigner": "mitre",
13-
"epss": 0.37,
13+
"epss": 0.53,
1414
"enisaIdProduct": [
1515
{
1616
"id": "e6ee7c0f-7f6e-3a37-995b-41e808ecca97",

0 commit comments

Comments
 (0)