Skip to content

File tree

advisories/unreviewed/2023/07/GHSA-m4w8-93pm-87f6/GHSA-m4w8-93pm-87f6.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-m4w8-93pm-87f6",
4-
"modified": "2024-04-04T06:06:37Z",
4+
"modified": "2026-06-01T12:30:29Z",
55
"published": "2023-07-13T09:30:28Z",
66
"aliases": [
77
"CVE-2023-1547"
88
],
9-
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik allows SQL Injection through SOAP Parameter Tampering, Command Line Execution through SQL Injection.This issue affects Parkmatik: before 02.01-a51.\n\n",
9+
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik allows SQL Injection through SOAP Parameter Tampering, Command Line Execution through SQL Injection.This issue affects Parkmatik: before 02.01-a51.",
1010
"severity": [
1111
{
1212
"type": "CVSS_V3",
@@ -19,6 +19,10 @@
1919
"type": "ADVISORY",
2020
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1547"
2121
},
22+
{
23+
"type": "WEB",
24+
"url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0404"
25+
},
2226
{
2327
"type": "WEB",
2428
"url": "https://www.usom.gov.tr/bildirim/tr-23-0404"

advisories/unreviewed/2026/06/GHSA-2r5m-76wx-56gx/GHSA-2r5m-76wx-56gx.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-2r5m-76wx-56gx",
4-
"modified": "2026-06-01T09:31:14Z",
4+
"modified": "2026-06-01T12:30:31Z",
55
"published": "2026-06-01T09:31:14Z",
66
"aliases": [
77
"CVE-2026-45360"
@@ -21,6 +21,10 @@
2121
{
2222
"type": "WEB",
2323
"url": "https://lists.apache.org/thread/q227dghjwgfz8xsxrf2pwpz4wk43zm83"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "http://www.openwall.com/lists/oss-security/2026/05/31/12"
2428
}
2529
],
2630
"database_specific": {

advisories/unreviewed/2026/06/GHSA-4c39-fwgj-4vq7/GHSA-4c39-fwgj-4vq7.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-4c39-fwgj-4vq7",
4-
"modified": "2026-06-01T09:31:15Z",
4+
"modified": "2026-06-01T12:30:31Z",
55
"published": "2026-06-01T09:31:15Z",
66
"aliases": [
77
"CVE-2026-49361"
@@ -17,6 +17,10 @@
1717
{
1818
"type": "WEB",
1919
"url": "https://lists.apache.org/thread/dccw6tj0njwtmvbftq13mw7fdhsok373"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "http://www.openwall.com/lists/oss-security/2026/05/30/5"
2024
}
2125
],
2226
"database_specific": {
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-4j5r-6h7v-59cc",
4+
"modified": "2026-06-01T12:30:31Z",
5+
"published": "2026-06-01T12:30:31Z",
6+
"aliases": [
7+
"CVE-2026-10245"
8+
],
9+
"details": "A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10245"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/timeflies123/cve/issues/3"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://vuldb.com/cve/CVE-2026-10245"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/submit/823937"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/vuln/367523"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/367523/cti"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://www.sourcecodester.com"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-79"
54+
],
55+
"severity": "LOW",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-06-01T11:16:23Z"
59+
}
60+
}

advisories/unreviewed/2026/06/GHSA-6hcw-qqr8-pjj8/GHSA-6hcw-qqr8-pjj8.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-6hcw-qqr8-pjj8",
4-
"modified": "2026-06-01T09:31:13Z",
4+
"modified": "2026-06-01T12:30:30Z",
55
"published": "2026-06-01T09:31:13Z",
66
"aliases": [
77
"CVE-2026-40961"
@@ -21,6 +21,10 @@
2121
{
2222
"type": "WEB",
2323
"url": "https://lists.apache.org/thread/qmt8ksh7gty6b8hr9w294t94j36jdv1q"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "http://www.openwall.com/lists/oss-security/2026/05/31/2"
2428
}
2529
],
2630
"database_specific": {

advisories/unreviewed/2026/06/GHSA-89cj-xrpx-j79m/GHSA-89cj-xrpx-j79m.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-89cj-xrpx-j79m",
4-
"modified": "2026-06-01T09:31:14Z",
4+
"modified": "2026-06-01T12:30:30Z",
55
"published": "2026-06-01T09:31:13Z",
66
"aliases": [
77
"CVE-2026-40861"
@@ -21,6 +21,10 @@
2121
{
2222
"type": "WEB",
2323
"url": "https://lists.apache.org/thread/823334db2559xjlwt59gpzjz47thnscl"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "http://www.openwall.com/lists/oss-security/2026/05/31/1"
2428
}
2529
],
2630
"database_specific": {
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-8wv4-h2m6-qrm3",
4+
"modified": "2026-06-01T12:30:32Z",
5+
"published": "2026-06-01T12:30:32Z",
6+
"aliases": [
7+
"CVE-2026-10250"
8+
],
9+
"details": "A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10250"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/zhengdexu-bot/zhengdexu/issues/2"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://itsourcecode.com"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/cve/CVE-2026-10250"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/submit/824047"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/367528"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://vuldb.com/vuln/367528/cti"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-74"
54+
],
55+
"severity": "MODERATE",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-06-01T11:16:24Z"
59+
}
60+
}

advisories/unreviewed/2026/06/GHSA-95v7-h9j5-gvjr/GHSA-95v7-h9j5-gvjr.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-95v7-h9j5-gvjr",
4-
"modified": "2026-06-01T09:31:14Z",
4+
"modified": "2026-06-01T12:30:31Z",
55
"published": "2026-06-01T09:31:13Z",
66
"aliases": [
77
"CVE-2026-41017"
@@ -21,6 +21,10 @@
2121
{
2222
"type": "WEB",
2323
"url": "https://lists.apache.org/thread/9jx0sk49c1250zflx0q3clc717qgjdch"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "http://www.openwall.com/lists/oss-security/2026/05/31/6"
2428
}
2529
],
2630
"database_specific": {
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-9pjg-jh77-2mjg",
4+
"modified": "2026-06-01T12:30:32Z",
5+
"published": "2026-06-01T12:30:32Z",
6+
"aliases": [
7+
"CVE-2026-25600"
8+
],
9+
"details": "The PDBM application relies on a static, hard‑coded secret embedded \nin the PDBM.exe executable. This secret is used by the application’s \nencryption routines, including the function responsible for decrypting \ncredentials stored in the product’s configuration file. Because the \nsecret is constant across installations, any attacker with sufficient \nlocal privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored \npassword and authenticate as the user defined in the configuration file.\n In the affected version, this user account is configured with \nadministrative privileges, granting full access to PDBM’s management \ninterface and its underlying operational functions.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25600"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://www.cert.si/en/cve-2026-25600"
25+
}
26+
],
27+
"database_specific": {
28+
"cwe_ids": [
29+
"CWE-798"
30+
],
31+
"severity": "MODERATE",
32+
"github_reviewed": false,
33+
"github_reviewed_at": null,
34+
"nvd_published_at": "2026-06-01T11:16:24Z"
35+
}
36+
}
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-cvf2-cgfw-jqr4",
4+
"modified": "2026-06-01T12:30:31Z",
5+
"published": "2026-06-01T12:30:31Z",
6+
"aliases": [
7+
"CVE-2026-10246"
8+
],
9+
"details": "A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10246"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/timeflies123/cve/issues/4"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://vuldb.com/cve/CVE-2026-10246"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/submit/823941"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/vuln/367524"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/367524/cti"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://www.sourcecodester.com"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-79"
54+
],
55+
"severity": "LOW",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-06-01T11:16:23Z"
59+
}
60+
}

0 commit comments

Comments
 (0)