Skip to content

Commit a7b90ac

Browse files
Advisory Database Sync
1 parent 8ed2aea commit a7b90ac

59 files changed

Lines changed: 1158 additions & 129 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎advisories/unreviewed/2026/08/GHSA-cq86-v72j-qxrj/GHSA-cq86-v72j-qxrj.json‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-cq86-v72j-qxrj",
4-
"modified": "2026-09-17T21:31:22Z",
4+
"modified": "2026-09-18T12:31:14Z",
55
"published": "2026-08-12T21:31:43Z",
66
"aliases": [
77
"CVE-2026-73433"
@@ -35,6 +35,10 @@
3535
"type": "WEB",
3636
"url": "https://access.redhat.com/errata/RHSA-2026:65959"
3737
},
38+
{
39+
"type": "WEB",
40+
"url": "https://access.redhat.com/errata/RHSA-2026:68642"
41+
},
3842
{
3943
"type": "WEB",
4044
"url": "https://access.redhat.com/errata/RHSA-2026:68644"

‎advisories/unreviewed/2026/08/GHSA-wfhj-v65x-vjp5/GHSA-wfhj-v65x-vjp5.json‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-wfhj-v65x-vjp5",
4-
"modified": "2026-09-17T21:31:22Z",
4+
"modified": "2026-09-18T12:31:14Z",
55
"published": "2026-08-12T21:31:43Z",
66
"aliases": [
77
"CVE-2026-73434"
@@ -35,6 +35,10 @@
3535
"type": "WEB",
3636
"url": "https://access.redhat.com/errata/RHSA-2026:65959"
3737
},
38+
{
39+
"type": "WEB",
40+
"url": "https://access.redhat.com/errata/RHSA-2026:68642"
41+
},
3842
{
3943
"type": "WEB",
4044
"url": "https://access.redhat.com/errata/RHSA-2026:68644"

‎advisories/unreviewed/2026/09/GHSA-2963-vmc7-jqxw/GHSA-2963-vmc7-jqxw.json‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-2963-vmc7-jqxw",
4-
"modified": "2026-09-18T06:31:30Z",
4+
"modified": "2026-09-18T12:31:15Z",
55
"published": "2026-09-18T06:31:30Z",
66
"aliases": [
77
"CVE-2026-89007"
88
],
99
"details": "The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -20,8 +25,10 @@
2025
}
2126
],
2227
"database_specific": {
23-
"cwe_ids": [],
24-
"severity": null,
28+
"cwe_ids": [
29+
"CWE-862"
30+
],
31+
"severity": "LOW",
2532
"github_reviewed": false,
2633
"github_reviewed_at": null,
2734
"nvd_published_at": "2026-09-18T06:16:41Z"

‎advisories/unreviewed/2026/09/GHSA-332v-j356-q3mj/GHSA-332v-j356-q3mj.json‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-332v-j356-q3mj",
4-
"modified": "2026-09-18T06:31:29Z",
4+
"modified": "2026-09-18T12:31:14Z",
55
"published": "2026-09-18T06:31:29Z",
66
"aliases": [
77
"CVE-2026-81340"
88
],
99
"details": "The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -20,8 +25,10 @@
2025
}
2126
],
2227
"database_specific": {
23-
"cwe_ids": [],
24-
"severity": null,
28+
"cwe_ids": [
29+
"CWE-639"
30+
],
31+
"severity": "LOW",
2532
"github_reviewed": false,
2633
"github_reviewed_at": null,
2734
"nvd_published_at": "2026-09-18T06:16:39Z"

‎advisories/unreviewed/2026/09/GHSA-35qw-6f3x-m64f/GHSA-35qw-6f3x-m64f.json‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,9 @@
2525
}
2626
],
2727
"database_specific": {
28-
"cwe_ids": [],
28+
"cwe_ids": [
29+
"CWE-693"
30+
],
2931
"severity": "MODERATE",
3032
"github_reviewed": false,
3133
"github_reviewed_at": null,
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3x2v-v38v-4mgx",
4+
"modified": "2026-09-18T12:31:20Z",
5+
"published": "2026-09-18T12:31:20Z",
6+
"aliases": [
7+
"CVE-2026-28197"
8+
],
9+
"details": "An authenticated, low-privileged user with access to the NetBackup Flex \nOS management shell could supply a specially crafted input to a \nprivileged administrative command, causing it to execute arbitrary code \nwith root-level permissions. Successful exploitation grants the attacker\n unrestricted control over the Flex appliance host and all hosted \ncontainers, fully compromising confidentiality, integrity, and \navailability.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28197"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/cohesity/SecAdvisory/blob/master/COH-2026-0001.md"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2026-28197"
33+
}
34+
],
35+
"database_specific": {
36+
"cwe_ids": [
37+
"CWE-88"
38+
],
39+
"severity": "CRITICAL",
40+
"github_reviewed": false,
41+
"github_reviewed_at": null,
42+
"nvd_published_at": "2026-09-18T12:17:24Z"
43+
}
44+
}

‎advisories/unreviewed/2026/09/GHSA-3x7x-rg4h-cpjq/GHSA-3x7x-rg4h-cpjq.json‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-3x7x-rg4h-cpjq",
4-
"modified": "2026-09-18T06:31:29Z",
4+
"modified": "2026-09-18T12:31:14Z",
55
"published": "2026-09-18T06:31:29Z",
66
"aliases": [
77
"CVE-2026-85350"
88
],
99
"details": "The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -20,8 +25,10 @@
2025
}
2126
],
2227
"database_specific": {
23-
"cwe_ids": [],
24-
"severity": null,
28+
"cwe_ids": [
29+
"CWE-287"
30+
],
31+
"severity": "MODERATE",
2532
"github_reviewed": false,
2633
"github_reviewed_at": null,
2734
"nvd_published_at": "2026-09-18T06:16:40Z"

‎advisories/unreviewed/2026/09/GHSA-43h4-q789-j3pr/GHSA-43h4-q789-j3pr.json‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-43h4-q789-j3pr",
4-
"modified": "2026-09-18T06:31:30Z",
4+
"modified": "2026-09-18T12:31:15Z",
55
"published": "2026-09-18T06:31:30Z",
66
"aliases": [
77
"CVE-2026-88798"
88
],
99
"details": "The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -20,8 +25,10 @@
2025
}
2126
],
2227
"database_specific": {
23-
"cwe_ids": [],
24-
"severity": null,
28+
"cwe_ids": [
29+
"CWE-400"
30+
],
31+
"severity": "MODERATE",
2532
"github_reviewed": false,
2633
"github_reviewed_at": null,
2734
"nvd_published_at": "2026-09-18T06:16:41Z"

‎advisories/unreviewed/2026/09/GHSA-4778-xmgc-pc88/GHSA-4778-xmgc-pc88.json‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-4778-xmgc-pc88",
4-
"modified": "2026-09-18T06:31:29Z",
4+
"modified": "2026-09-18T12:31:14Z",
55
"published": "2026-09-18T06:31:29Z",
66
"aliases": [
77
"CVE-2026-87770"
88
],
99
"details": "The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -20,8 +25,10 @@
2025
}
2126
],
2227
"database_specific": {
23-
"cwe_ids": [],
24-
"severity": null,
28+
"cwe_ids": [
29+
"CWE-89"
30+
],
31+
"severity": "HIGH",
2532
"github_reviewed": false,
2633
"github_reviewed_at": null,
2734
"nvd_published_at": "2026-09-18T06:16:40Z"

‎advisories/unreviewed/2026/09/GHSA-49x6-35hm-mhc5/GHSA-49x6-35hm-mhc5.json‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-49x6-35hm-mhc5",
4-
"modified": "2026-09-18T06:31:29Z",
4+
"modified": "2026-09-18T12:31:14Z",
55
"published": "2026-09-18T06:31:29Z",
66
"aliases": [
77
"CVE-2026-84902"
88
],
99
"details": "The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -20,8 +25,10 @@
2025
}
2126
],
2227
"database_specific": {
23-
"cwe_ids": [],
24-
"severity": null,
28+
"cwe_ids": [
29+
"CWE-79"
30+
],
31+
"severity": "MODERATE",
2532
"github_reviewed": false,
2633
"github_reviewed_at": null,
2734
"nvd_published_at": "2026-09-18T06:16:39Z"

0 commit comments

Comments
 (0)