Skip to content

File tree

advisories/unreviewed/2026/06/GHSA-xq96-f7x8-gfx3/GHSA-xq96-f7x8-gfx3.json

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-xq96-f7x8-gfx3",
4-
"modified": "2026-08-19T18:31:58Z",
4+
"modified": "2026-08-24T06:30:28Z",
55
"published": "2026-06-30T09:31:35Z",
66
"aliases": [
77
"CVE-2026-14164"
@@ -55,6 +55,14 @@
5555
"type": "WEB",
5656
"url": "https://access.redhat.com/errata/RHSA-2026:56954"
5757
},
58+
{
59+
"type": "WEB",
60+
"url": "https://access.redhat.com/errata/RHSA-2026:58573"
61+
},
62+
{
63+
"type": "WEB",
64+
"url": "https://access.redhat.com/errata/RHSA-2026:58574"
65+
},
5866
{
5967
"type": "WEB",
6068
"url": "https://access.redhat.com/security/cve/CVE-2026-14164"
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2hwj-pvrj-8rcc",
4+
"modified": "2026-08-24T06:30:29Z",
5+
"published": "2026-08-24T06:30:29Z",
6+
"aliases": [
7+
"CVE-2026-78198"
8+
],
9+
"details": "A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78198"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/wsx138/cve/issues/4"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://vuldb.com/cve/CVE-2026-78198"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/submit/886037"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/vuln/394575"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/394575/cti"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://www.sourcecodester.com"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-74"
54+
],
55+
"severity": "MODERATE",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-08-24T06:19:46Z"
59+
}
60+
}
Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3v3q-h6jq-r694",
4+
"modified": "2026-08-24T06:30:29Z",
5+
"published": "2026-08-24T06:30:29Z",
6+
"aliases": [
7+
"CVE-2026-78196"
8+
],
9+
"details": "A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument _display_name results in path traversal. The attack requires a local approach. Upgrading to version 8.0.1 is able to mitigate this issue. The patch is identified as c6900b1ed06fcc3ca4b09651348974ac5b95e4e6. The affected component should be upgraded.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78196"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/achorein/expo-share-intent/pull/221"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/achorein/expo-share-intent/commit/c6900b1ed06fcc3ca4b09651348974ac5b95e4e6"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/achorein/expo-share-intent"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/achorein/expo-share-intent/releases/tag/v8.0.1"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/cve/CVE-2026-78196"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://vuldb.com/submit/885425"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://vuldb.com/vuln/394573"
53+
},
54+
{
55+
"type": "WEB",
56+
"url": "https://vuldb.com/vuln/394573/cti"
57+
}
58+
],
59+
"database_specific": {
60+
"cwe_ids": [
61+
"CWE-22"
62+
],
63+
"severity": "MODERATE",
64+
"github_reviewed": false,
65+
"github_reviewed_at": null,
66+
"nvd_published_at": "2026-08-24T05:16:55Z"
67+
}
68+
}
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-4cgq-vq27-gxqx",
4+
"modified": "2026-08-24T06:30:29Z",
5+
"published": "2026-08-24T06:30:29Z",
6+
"aliases": [
7+
"CVE-2026-59561"
8+
],
9+
"details": "Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes \"Open Terminal\".",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "WEB",
24+
"url": "https://github.com/sakura-editor/sakura/security/advisories/GHSA-6x2x-729r-wjh5"
25+
},
26+
{
27+
"type": "ADVISORY",
28+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59561"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/sakura-editor/sakura/releases/tag/v2.4.3"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://jvn.jp/en/jp/JVN74538868"
37+
}
38+
],
39+
"database_specific": {
40+
"cwe_ids": [
41+
"CWE-78"
42+
],
43+
"severity": "HIGH",
44+
"github_reviewed": false,
45+
"github_reviewed_at": null,
46+
"nvd_published_at": "2026-08-24T05:16:55Z"
47+
}
48+
}
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-4x7g-69qr-g9rf",
4+
"modified": "2026-08-24T06:30:28Z",
5+
"published": "2026-08-24T06:30:28Z",
6+
"aliases": [
7+
"CVE-2026-78182"
8+
],
9+
"details": "A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78182"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://ucn9h68n9289.feishu.cn/docx/WgJYd7q4CopTQKxqWuWcJEpinde?from=from_copylink"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://vuldb.com/cve/CVE-2026-78182"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/submit/885103"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/vuln/394566"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/394566/cti"
45+
}
46+
],
47+
"database_specific": {
48+
"cwe_ids": [
49+
"CWE-74"
50+
],
51+
"severity": "MODERATE",
52+
"github_reviewed": false,
53+
"github_reviewed_at": null,
54+
"nvd_published_at": "2026-08-24T04:16:59Z"
55+
}
56+
}
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-522q-26rg-w3gh",
4+
"modified": "2026-08-24T06:30:28Z",
5+
"published": "2026-08-24T06:30:28Z",
6+
"aliases": [
7+
"CVE-2026-78185"
8+
],
9+
"details": "A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/cust_edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78185"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/ltranquility/vuln_submit/issues/27"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://itsourcecode.com"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/cve/CVE-2026-78185"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/submit/885182"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/394567"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://vuldb.com/vuln/394567/cti"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-74"
54+
],
55+
"severity": "LOW",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-08-24T04:16:59Z"
59+
}
60+
}
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-5fvj-c4j7-5h8h",
4+
"modified": "2026-08-24T06:30:29Z",
5+
"published": "2026-08-24T06:30:29Z",
6+
"aliases": [
7+
"CVE-2026-78201"
8+
],
9+
"details": "A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78201"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/microwaveabi/vul/issues/8"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://itsourcecode.com"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/cve/CVE-2026-78201"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/submit/886158"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/394578"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://vuldb.com/vuln/394578/cti"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-74"
54+
],
55+
"severity": "MODERATE",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-08-24T06:21:09Z"
59+
}
60+
}

0 commit comments

Comments
 (0)