Skip to content

Commit 77d8af2

Browse files
Advisory Database Sync
1 parent 00a770b commit 77d8af2

107 files changed

Lines changed: 3374 additions & 62 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎advisories/unreviewed/2022/08/GHSA-qqpf-7vhq-8phw/GHSA-qqpf-7vhq-8phw.json‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-qqpf-7vhq-8phw",
4-
"modified": "2022-08-26T00:03:36Z",
4+
"modified": "2026-10-09T15:31:14Z",
55
"published": "2022-08-24T00:00:28Z",
66
"aliases": [
77
"CVE-2022-2946"
@@ -31,6 +31,10 @@
3131
"type": "WEB",
3232
"url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html"
3333
},
34+
{
35+
"type": "WEB",
36+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD"
37+
},
3438
{
3539
"type": "WEB",
3640
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C72HDIMR3KTTAO7QGTXWUMPBNFUFIBRD"

‎advisories/unreviewed/2026/09/GHSA-mjj6-px65-jq92/GHSA-mjj6-px65-jq92.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-mjj6-px65-jq92",
4-
"modified": "2026-09-27T03:31:04Z",
4+
"modified": "2026-10-09T15:31:14Z",
55
"published": "2026-09-27T03:31:04Z",
66
"aliases": [
77
"CVE-2026-100833"

‎advisories/unreviewed/2026/10/GHSA-25mp-f6qq-hg3f/GHSA-25mp-f6qq-hg3f.json‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,9 @@
2525
}
2626
],
2727
"database_specific": {
28-
"cwe_ids": [],
28+
"cwe_ids": [
29+
"CWE-352"
30+
],
2931
"severity": "MODERATE",
3032
"github_reviewed": false,
3133
"github_reviewed_at": null,

‎advisories/unreviewed/2026/10/GHSA-29m4-fpp8-q5f8/GHSA-29m4-fpp8-q5f8.json‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,8 @@
2626
],
2727
"database_specific": {
2828
"cwe_ids": [
29-
"CWE-119"
29+
"CWE-119",
30+
"CWE-787"
3031
],
3132
"severity": "HIGH",
3233
"github_reviewed": false,
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2w3c-qw6p-h26m",
4+
"modified": "2026-10-09T15:31:35Z",
5+
"published": "2026-10-09T15:31:35Z",
6+
"aliases": [
7+
"CVE-2026-78796"
8+
],
9+
"details": "An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to execute arbitrary code via the www\\cgi-bin\\upgrade file",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78796"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://github.com/PRISMI-Team/VulnDisclos/blob/main/Routers/Netcore/unauthorized-rce.md"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://pastebin.com/vAh2kEeT"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [],
28+
"severity": null,
29+
"github_reviewed": false,
30+
"github_reviewed_at": null,
31+
"nvd_published_at": "2026-10-09T15:17:15Z"
32+
}
33+
}
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2xrm-qggp-hr4m",
4+
"modified": "2026-10-09T15:31:33Z",
5+
"published": "2026-10-09T15:31:33Z",
6+
"aliases": [
7+
"CVE-2026-108104"
8+
],
9+
"details": "Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that returns pooled buffers twice when replacement allocation fails. Attackers can supply framed data with a large declared chunk length to trigger OutOfMemoryError, causing shared backing arrays that expose or overwrite other streams' decompressed data.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "WEB",
24+
"url": "https://github.com/xerial/snappy-java/security/advisories/GHSA-c73m-r934-8qvg"
25+
},
26+
{
27+
"type": "ADVISORY",
28+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-108104"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/xerial/snappy-java/commit/139a53090a6662298924fd75d21f4769b4a219ea"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/xerial/snappy-java"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/xerial/snappy-java/blob/v1.1.10.9/src/main/java/org/xerial/snappy/SnappyFramedInputStream.java#L243"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://github.com/xerial/snappy-java/releases/tag/v1.1.10.10"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://www.vulncheck.com/advisories/xerial-snappy-java-1.1.7.4-before-1.1.10.10-double-release-of-pooled-buffers-in-snappyframedinputstream"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-415"
54+
],
55+
"severity": "MODERATE",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-10-09T15:17:11Z"
59+
}
60+
}
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2xxc-vw34-6v9p",
4+
"modified": "2026-10-09T15:31:31Z",
5+
"published": "2026-10-09T15:31:31Z",
6+
"aliases": [
7+
"CVE-2026-94067"
8+
],
9+
"details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94067"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://patchstack.com/database/wordpress/theme/thevoux-wp/vulnerability/wordpress-the-voux-theme-6-9-5-local-file-inclusion-vulnerability?_s_id=cve"
25+
}
26+
],
27+
"database_specific": {
28+
"cwe_ids": [
29+
"CWE-98"
30+
],
31+
"severity": "HIGH",
32+
"github_reviewed": false,
33+
"github_reviewed_at": null,
34+
"nvd_published_at": "2026-10-09T14:17:26Z"
35+
}
36+
}
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-337v-466h-8gh6",
4+
"modified": "2026-10-09T15:31:33Z",
5+
"published": "2026-10-09T15:31:33Z",
6+
"aliases": [
7+
"CVE-2026-108102"
8+
],
9+
"details": "Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "WEB",
24+
"url": "https://github.com/open5gs/open5gs/security/advisories/GHSA-37c3-hv4f-688p"
25+
},
26+
{
27+
"type": "ADVISORY",
28+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-108102"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/open5gs/open5gs/commit/88e64fc1f87e0d321364b3bb710ef6a8f274e568"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/open5gs/open5gs"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/open5gs/open5gs/blob/v2.8.0/lib/pfcp/types.c#L581-L635"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://www.vulncheck.com/advisories/open5gs-through-2.8.0-heap-out-of-bounds-read-via-pfcp-volume-measurement-ie"
45+
}
46+
],
47+
"database_specific": {
48+
"cwe_ids": [
49+
"CWE-125"
50+
],
51+
"severity": "MODERATE",
52+
"github_reviewed": false,
53+
"github_reviewed_at": null,
54+
"nvd_published_at": "2026-10-09T15:17:10Z"
55+
}
56+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-33hw-v5j3-gx3r",
4+
"modified": "2026-10-09T15:31:30Z",
5+
"published": "2026-10-09T15:31:30Z",
6+
"aliases": [
7+
"CVE-2026-8374"
8+
],
9+
"details": "Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V4",
13+
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:I/V:D/RE:H/U:Red"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8374"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://neodyme.io/en/advisories/cve-2026-8374"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://neodyme.io/en/blog/switchbot"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-1204"
34+
],
35+
"severity": "HIGH",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-10-09T13:17:11Z"
39+
}
40+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-39g8-j5g5-gfjq",
4+
"modified": "2026-10-09T15:31:31Z",
5+
"published": "2026-10-09T15:31:31Z",
6+
"aliases": [
7+
"CVE-2026-79363"
8+
],
9+
"details": "Cloudron 9.1.7 and 9.2 contain a stored cross-site scripting (XSS) vulnerability in the Branding Footer feature. An authenticated administrator can store crafted HTML containing JavaScript event handlers in the Footer setting. The stored value is rendered without sufficient sanitization on the public login / OpenID interaction page and in the System Event Log, causing attacker-controlled JavaScript to execute in the Cloudron web origin when an affected page is viewed.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79363"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://www.faydin.blog/cves/cves.html"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://www.faydin.blog/en/cves/CVE-2026-79363"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [],
28+
"severity": null,
29+
"github_reviewed": false,
30+
"github_reviewed_at": null,
31+
"nvd_published_at": "2026-10-09T14:17:22Z"
32+
}
33+
}

0 commit comments

Comments
 (0)