Skip to content

Commit 23d3688

Browse files
Sync EUVD catalog: Mon Apr 20 00:41:05 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 17f0f64 commit 23d3688

25 files changed

Lines changed: 2957 additions & 1 deletion
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2026-23681",
3+
"enisaUuid": "4720421f-f275-3a14-a8b9-659ea33b4f48",
4+
"description": "The EMC \u2013 Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's calendly shortcode in all versions up to, and including, 4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
5+
"datePublished": "Apr 19, 2026, 6:31:22 AM",
6+
"dateUpdated": "Apr 19, 2026, 6:31:22 AM",
7+
"baseScore": 6.4,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
10+
"references": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d5653ebe-7145-4b1c-94f8-ca87ed0dc4f5?source=cve\nhttps://plugins.trac.wordpress.org/changeset/3466576/embed-calendly-scheduling\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-0868\n",
11+
"aliases": "CVE-2026-0868\n",
12+
"assigner": "Wordfence",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "331e9b12-bd6c-3afb-9bc8-46dcef96e24f",
17+
"product": {
18+
"name": "EMC \u2013 Easily Embed Calendly Scheduling"
19+
},
20+
"product_version": "0 \u22644.4"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "8215e974-9ebb-3a41-ab1d-c79e8dc7105d",
26+
"vendor": {
27+
"name": "turn2honey"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2026-23682",
3+
"enisaUuid": "3ea31625-3768-3deb-ac16-ffbfe30bb915",
4+
"description": "A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.",
5+
"datePublished": "Apr 19, 2026, 6:31:22 AM",
6+
"dateUpdated": "Apr 19, 2026, 6:31:22 AM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X",
10+
"references": "https://vuldb.com/vuln/358196\nhttps://vuldb.com/vuln/358196/cti\nhttps://vuldb.com/submit/785303\nhttps://github.com/Litengzheng/vul_db/blob/main/WL-WN579A3/vul_16/README.md\nhttps://dl.wavlink.com/firmware/RD/WINSTAR_WN579A3-A-2026-03-10-94f93d4-WO-mt7628-squashfs-sysupgrade.bin\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6559\n",
11+
"aliases": "CVE-2026-6559\nGHSA-x8cm-r99c-gv26\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "264b72c2-2554-3c19-ae4a-abeac4bf8987",
17+
"product": {
18+
"name": "WL-WN579A3"
19+
},
20+
"product_version": "220323"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "5f6c5ff9-13d8-3e6f-ab17-3f6bdfe15028",
26+
"vendor": {
27+
"name": "WAVLINK"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2026-23684",
3+
"enisaUuid": "33b252f5-ba6b-3b38-bbca-6ceec978109d",
4+
"description": "A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_BasicSSID of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "Apr 19, 2026, 9:30:13 AM",
6+
"dateUpdated": "Apr 19, 2026, 9:30:13 AM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/358197\nhttps://vuldb.com/vuln/358197/cti\nhttps://vuldb.com/submit/788021\nhttps://github.com/xiaohaiyang-ai/CVE-Reports/blob/main/Vulnerability-Report.md\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6560\n",
11+
"aliases": "CVE-2026-6560\nGHSA-m9r6-cg89-ghg2\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0126b857-74cb-30ff-9a92-833166a44b4c",
17+
"product": {
18+
"name": "Magic B0"
19+
},
20+
"product_version": "100R002"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "1391ca92-6a49-3547-973a-468d5ef44ff4",
26+
"vendor": {
27+
"name": "H3C"
28+
}
29+
}
30+
]
31+
}
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
{
2+
"id": "EUVD-2026-23686",
3+
"enisaUuid": "66809a10-43a0-39bf-8c3c-320ec2adb543",
4+
"description": "A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "Apr 19, 2026, 9:30:13 AM",
6+
"dateUpdated": "Apr 19, 2026, 9:30:13 AM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/358198\nhttps://vuldb.com/vuln/358198/cti\nhttps://vuldb.com/submit/788038\nhttps://github.com/zzk6th/my-cve-notes/blob/main/EyouCMS%20Arbitrary%20File%20Copy%20Vulnerability%20in%20edit_adminlogo()%20Leading%20to%20Sensitive%20Information%20Disclosure.md\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6561\n",
11+
"aliases": "CVE-2026-6561\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "2f1d0675-c4f4-371e-88e4-c7069018989c",
17+
"product": {
18+
"name": "EyouCMS"
19+
},
20+
"product_version": "1.7.0"
21+
},
22+
{
23+
"id": "64e9b9ad-1d37-3009-ad76-66bbceddfbc1",
24+
"product": {
25+
"name": "EyouCMS"
26+
},
27+
"product_version": "1.7.1"
28+
}
29+
],
30+
"enisaIdVendor": [
31+
{
32+
"id": "231ce8cb-28ca-3422-8629-ef650255180b",
33+
"vendor": {
34+
"name": "n/a"
35+
}
36+
}
37+
]
38+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2026-23688",
3+
"enisaUuid": "74f96374-c93e-334b-828b-57fe12dc94de",
4+
"description": "A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a manipulation of the argument keyword can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "Apr 19, 2026, 9:30:13 AM",
6+
"dateUpdated": "Apr 19, 2026, 9:30:13 AM",
7+
"baseScore": 6.9,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/358199\nhttps://vuldb.com/vuln/358199/cti\nhttps://vuldb.com/submit/789501\nhttps://thinhneee.github.io/posts/muucmf-sqli/\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6562\n",
11+
"aliases": "CVE-2026-6562\nGHSA-7786-mqff-chgr\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "08cb6fad-5499-3722-b3e3-8e641b6da3c3",
17+
"product": {
18+
"name": "muucmf"
19+
},
20+
"product_version": "1.9.5.20260309"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "3c9b5fe1-509f-3f1b-8c60-2096aa8f93e1",
26+
"vendor": {
27+
"name": "dameng100"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2026-23690",
3+
"enisaUuid": "80aa3c6f-3e7e-34d2-9ca4-f2b7669eb950",
4+
"description": "A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "Apr 19, 2026, 9:30:13 AM",
6+
"dateUpdated": "Apr 19, 2026, 9:30:13 AM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/358200\nhttps://vuldb.com/vuln/358200/cti\nhttps://vuldb.com/submit/789531\nhttps://github.com/K4ptor/H3C-routers-vulnerability/\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6563\n",
11+
"aliases": "CVE-2026-6563\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "4e765834-7eef-3cfd-82bd-3a7040b4b691",
17+
"product": {
18+
"name": "Magic B1"
19+
},
20+
"product_version": "100R004"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "7192acd7-d3e3-35b5-a524-9aff2ed557b2",
26+
"vendor": {
27+
"name": "H3C"
28+
}
29+
}
30+
]
31+
}
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
{
2+
"id": "EUVD-2026-23692",
3+
"enisaUuid": "2f01194a-840c-308c-90da-57f69d744c4b",
4+
"description": "A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.",
5+
"datePublished": "Apr 19, 2026, 12:31:15 PM",
6+
"dateUpdated": "Apr 19, 2026, 12:31:15 PM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
10+
"references": "https://vuldb.com/vuln/358201\nhttps://vuldb.com/vuln/358201/cti\nhttps://vuldb.com/submit/789924\nhttps://github.com/cailiujia/CVE\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6564\n",
11+
"aliases": "CVE-2026-6564\nGHSA-vqmj-h423-xx64\n",
12+
"assigner": "VulDB",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "5f32fa05-2e3e-3031-a156-f09de39130e4",
17+
"product": {
18+
"name": "EMQX Enterprise"
19+
},
20+
"product_version": "6.1.0"
21+
},
22+
{
23+
"id": "67f484f5-29ec-334c-bd12-35766d2b1e32",
24+
"product": {
25+
"name": "EMQX Enterprise"
26+
},
27+
"product_version": "6.0"
28+
}
29+
],
30+
"enisaIdVendor": [
31+
{
32+
"id": "327d8bd7-b29a-39ac-9565-140719f9223f",
33+
"vendor": {
34+
"name": "EMQ"
35+
}
36+
}
37+
]
38+
}

0 commit comments

Comments
 (0)