Skip to content

Commit 79b6ee4

Browse files
Sync EUVD catalog: Tue Aug 18 00:15:14 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 6ea5cd2 commit 79b6ee4

3,727 files changed

Lines changed: 41848 additions & 18948 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2018-20337",
3+
"enisaUuid": "bd4051dc-3edd-3c41-8dd1-0492a4965eb7",
4+
"description": "Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system to access files or directories via the Web Client webserver.",
5+
"datePublished": "Jun 19, 2018, 7:00:00 PM",
6+
"dateUpdated": "Aug 17, 2026, 5:07:32 PM",
7+
"baseScore": null,
8+
"references": "https://www.onvio.nl/nieuws/cve-mirasys-vulnerability\nhttps://www.exploit-db.com/exploits/44907\n",
9+
"aliases": "GHSA-j23c-2cfm-f3m9\nCVE-2018-8727\n",
10+
"assigner": "mitre",
11+
"epss": 7.8,
12+
"enisaIdProduct": [
13+
{
14+
"id": "90d2fdb2-4aaf-3e2f-8e8c-2418cf034d14",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "3c26b97e-4dc4-346f-bec1-1849738f4292",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2019-2593",
3+
"enisaUuid": "f0c728c6-2d7f-3a8f-a265-04e17febefa9",
4+
"description": "Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.",
5+
"datePublished": "May 7, 2019, 5:07:57 PM",
6+
"dateUpdated": "Aug 17, 2026, 5:23:04 PM",
7+
"baseScore": null,
8+
"references": "https://www.onvio.nl/nieuws/ninjaforms-vulnerability\nhttps://wpvulndb.com/vulnerabilities/9272\nhttps://wpscan.com/vulnerability/e5898e0e-db43-4641-b2cd-f6a72cdb8993/\n",
9+
"aliases": "GHSA-mfw8-6m9g-8vvr\nCVE-2019-10869\n",
10+
"assigner": "mitre",
11+
"epss": 13.02,
12+
"enisaIdProduct": [
13+
{
14+
"id": "ebfa323a-180c-3fe8-a17d-dfefa1c7086d",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "013a228a-a31a-395e-a84c-c49f62ff7337",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}

advisories/2023/12/EUVD-2023-59129.json

Lines changed: 57 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,29 +1,76 @@
11
{
22
"id": "EUVD-2023-59129",
33
"enisaUuid": "d3af44fd-bf91-3363-9f3a-15e6a5ead69d",
4-
"description": "A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.\n\nA perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().\n\nWe recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.",
4+
"description": "A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.\n\n\n\nA perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().\n\n\n\nWe recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.",
55
"datePublished": "Dec 19, 2023, 2:09:14 PM",
6-
"dateUpdated": "Feb 13, 2025, 5:26:59 PM",
6+
"dateUpdated": "Aug 17, 2026, 2:11:22 PM",
77
"baseScore": 7.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
10-
"references": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=382c27f4ed28f803b1f1473ac2d8db0afc795a1b\nhttps://kernel.dance/382c27f4ed28f803b1f1473ac2d8db0afc795a1b\nhttps://lists.debian.org/debian-lts-announce/2024/01/msg00004.html\nhttps://lists.debian.org/debian-lts-announce/2024/01/msg00005.html\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-6931\n",
10+
"references": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=382c27f4ed28f803b1f1473ac2d8db0afc795a1b\nhttps://kernel.dance/382c27f4ed28f803b1f1473ac2d8db0afc795a1b\nhttps://lists.debian.org/debian-lts-announce/2024/01/msg00004.html\nhttps://lists.debian.org/debian-lts-announce/2024/01/msg00005.html\n",
1111
"aliases": "CVE-2023-6931\nGHSA-xv88-q3gm-mmjp\n",
1212
"assigner": "Google",
13-
"epss": 0.34,
13+
"epss": 0.72,
1414
"enisaIdProduct": [
1515
{
16-
"id": "2a553ef9-7d49-38b2-ac1d-18ea9528c283",
16+
"id": "1168627d-1c27-3af4-8ef2-4bc80b5061e3",
1717
"product": {
18-
"name": "Kernel"
19-
}
18+
"name": "Linux kernel",
19+
"vendor": {
20+
"name": "n/a"
21+
}
22+
},
23+
"product_version": "6.2.0 <6.6.7"
24+
},
25+
{
26+
"id": "26c8def9-cb50-3dae-843a-8153633ea6e2",
27+
"product": {
28+
"name": "Linux kernel",
29+
"vendor": {
30+
"name": "n/a"
31+
}
32+
},
33+
"product_version": "4.3.0 <4.19.302"
34+
},
35+
{
36+
"id": "3932d0dd-b1ab-35b0-ab60-aed862bedc02",
37+
"product": {
38+
"name": "Linux kernel",
39+
"vendor": {
40+
"name": "n/a"
41+
}
42+
},
43+
"product_version": "4.20.0 <5.4.264"
44+
},
45+
{
46+
"id": "484c82e5-6840-3273-afbf-d5dab6affec7",
47+
"product": {
48+
"name": "Linux kernel",
49+
"vendor": {
50+
"name": "n/a"
51+
}
52+
},
53+
"product_version": "5.5.0 <5.10.204"
54+
},
55+
{
56+
"id": "643bed60-0df9-3ab9-801e-45321d60c5f0",
57+
"product": {
58+
"name": "Linux kernel",
59+
"vendor": {
60+
"name": "n/a"
61+
}
62+
},
63+
"product_version": "5.11.0 <5.15.143"
2064
},
2165
{
22-
"id": "b4968a0e-5c7b-3e2b-b6ab-e61f4a1a6de1",
66+
"id": "826a79d5-b67a-32fc-9e9a-844c5bce6b07",
2367
"product": {
24-
"name": "Kernel"
68+
"name": "Linux kernel",
69+
"vendor": {
70+
"name": "n/a"
71+
}
2572
},
26-
"product_version": "4.3 <6.7"
73+
"product_version": "5.16.0 <6.1.68"
2774
}
2875
],
2976
"enisaIdVendor": [

advisories/2024/01/EUVD-2024-0459.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "4e9c3427-0aff-3862-a918-b9f48c80d302",
44
"description": "runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem (\"attack 2\"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run (\"attack 1\"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes (\"attack 3a\" and \"attack 3b\"). runc 1.1.12 includes patches for this issue.",
55
"datePublished": "Jan 31, 2024, 9:31:14 PM",
6-
"dateUpdated": "Aug 14, 2026, 12:04:32 PM",
6+
"dateUpdated": "Aug 17, 2026, 12:05:11 PM",
77
"baseScore": 8.6,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",

advisories/2024/10/EUVD-2024-2916.json

Lines changed: 22 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,11 +3,11 @@
33
"enisaUuid": "5807c4d5-6b28-3f75-abb2-38d836fd5d06",
44
"description": "A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.\u00a0 It is also possible to force a derived key to be all zeros instead of an unpredictable value.\u00a0 This may have follow-on implications for the Go TLS stack.",
55
"datePublished": "Oct 1, 2024, 6:17:29 PM",
6-
"dateUpdated": "Aug 15, 2026, 3:13:56 AM",
6+
"dateUpdated": "Aug 17, 2026, 12:08:17 PM",
77
"baseScore": 6.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
10-
"references": "https://access.redhat.com/errata/RHSA-2024:10133\nhttps://access.redhat.com/errata/RHSA-2024:7502\nhttps://access.redhat.com/errata/RHSA-2024:7550\nhttps://access.redhat.com/errata/RHSA-2024:8327\nhttps://access.redhat.com/errata/RHSA-2024:8678\nhttps://access.redhat.com/errata/RHSA-2024:8847\nhttps://access.redhat.com/errata/RHSA-2024:9551\nhttps://access.redhat.com/errata/RHSA-2025:2416\nhttps://access.redhat.com/errata/RHSA-2025:7118\nhttps://access.redhat.com/errata/RHSA-2025:7256\nhttps://access.redhat.com/errata/RHSA-2025:7624\nhttps://access.redhat.com/security/cve/CVE-2024-9355\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2315719\nhttps://github.com/golang-fips/openssl/pull/198\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2024:10133\nhttps://access.redhat.com/errata/RHSA-2024:7502\nhttps://access.redhat.com/errata/RHSA-2024:7550\nhttps://access.redhat.com/errata/RHSA-2024:8327\nhttps://access.redhat.com/errata/RHSA-2024:8678\nhttps://access.redhat.com/errata/RHSA-2024:8847\nhttps://access.redhat.com/errata/RHSA-2024:9551\nhttps://access.redhat.com/errata/RHSA-2025:2416\nhttps://access.redhat.com/errata/RHSA-2025:7118\nhttps://access.redhat.com/errata/RHSA-2025:7256\nhttps://access.redhat.com/errata/RHSA-2025:7624\nhttps://access.redhat.com/errata/RHSA-2026:55520\nhttps://access.redhat.com/errata/RHSA-2026:55525\nhttps://access.redhat.com/security/cve/CVE-2024-9355\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2315719\nhttps://github.com/golang-fips/openssl/pull/198\n",
1111
"aliases": "GHSA-3h3x-2hwv-hr52\nCVE-2024-9355\n",
1212
"assigner": "redhat",
1313
"epss": 0.3,
@@ -72,6 +72,16 @@
7272
},
7373
"product_version": "patch: 0:0.3.1-1.el9sat"
7474
},
75+
{
76+
"id": "80c283ff-d9bb-30e9-9d66-24a6f68f2566",
77+
"product": {
78+
"name": "Red Hat Enterprise Linux 9.6 Extended Update Support",
79+
"vendor": {
80+
"name": "Red Hat"
81+
}
82+
},
83+
"product_version": "patch: 0:0.23.0-1.el9_6.1"
84+
},
7585
{
7686
"id": "81ce9f9f-8560-387d-b58b-0b6551cd3dd7",
7787
"product": {
@@ -92,6 +102,16 @@
92102
},
93103
"product_version": "patch: 0:0.10-2.el7_9"
94104
},
105+
{
106+
"id": "92c90115-99f9-3fc9-bf0f-d561c08b7355",
107+
"product": {
108+
"name": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
109+
"vendor": {
110+
"name": "Red Hat"
111+
}
112+
},
113+
"product_version": "patch: 0:0.17.0-1.el9_2.1"
114+
},
95115
{
96116
"id": "a89cd996-49c0-390e-812b-51dd4a5a6390",
97117
"product": {

advisories/2024/10/EUVD-2024-3040.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "a829f1ef-f74c-3b88-abd7-9a1363649e48",
44
"description": "Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function.",
55
"datePublished": "Oct 31, 2024, 5:00:03 AM",
6-
"dateUpdated": "Aug 13, 2026, 3:25:37 PM",
6+
"dateUpdated": "Aug 17, 2026, 3:25:17 PM",
77
"baseScore": 9.3,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",

advisories/2025/01/EUVD-2024-50581.json

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "05e3a76c-8055-388a-9e22-2ca124296b93",
44
"description": "A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.",
55
"datePublished": "Jan 14, 2025, 5:37:16 PM",
6-
"dateUpdated": "Aug 16, 2026, 6:44:51 PM",
6+
"dateUpdated": "Aug 17, 2026, 1:18:43 PM",
77
"baseScore": 7.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
@@ -912,16 +912,6 @@
912912
},
913913
"product_version": "patch: v4.18.0-202502101302.p0.g763313c.assembly.stream.el9"
914914
},
915-
{
916-
"id": "6ecfde44-51ea-3115-be94-ff47b4a2174a",
917-
"product": {
918-
"name": "Compliance Operator 1",
919-
"vendor": {
920-
"name": "Red Hat"
921-
}
922-
},
923-
"product_version": "patch: 1.8.0"
924-
},
925915
{
926916
"id": "7337e4e2-9030-3508-8730-d792aa37469e",
927917
"product": {
@@ -1182,6 +1172,16 @@
11821172
},
11831173
"product_version": "patch: v4.18.0-202501230001.p0.g7ec03e9.assembly.stream.el9"
11841174
},
1175+
{
1176+
"id": "938b5d37-eab4-37c4-9689-18658b02ebf2",
1177+
"product": {
1178+
"name": "OpenShift Compliance Operator 1",
1179+
"vendor": {
1180+
"name": "Red Hat"
1181+
}
1182+
},
1183+
"product_version": "patch: 1.8.0"
1184+
},
11851185
{
11861186
"id": "9400f548-6ee9-3ac9-a678-2094b3fd32a7",
11871187
"product": {

advisories/2025/02/EUVD-2025-2098.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "ae3690f2-258c-3b04-9a61-d53956eb284f",
44
"description": "A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.",
55
"datePublished": "Feb 12, 2025, 2:27:45 PM",
6-
"dateUpdated": "Aug 16, 2026, 5:04:08 PM",
6+
"dateUpdated": "Aug 17, 2026, 10:58:31 AM",
77
"baseScore": 8.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
@@ -33,9 +33,9 @@
3333
"product_version": "patch: 1:27.2-11.el9_5.1"
3434
},
3535
{
36-
"id": "2181d66c-e6f8-3197-a1c4-fe4a8fa049b5",
36+
"id": "1cca1330-c465-3796-ad3e-6fd7c30b7eb5",
3737
"product": {
38-
"name": "Builds for Red Hat OpenShift 1.3.1",
38+
"name": "Builds for Red Hat OpenShift 1.3.2",
3939
"vendor": {
4040
"name": "Red Hat"
4141
}

advisories/2025/03/EUVD-2025-7628.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "283c9076-26e9-34e5-a6f3-df737883bed8",
44
"description": "A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.",
55
"datePublished": "Mar 4, 2025, 3:14:47 PM",
6-
"dateUpdated": "Aug 4, 2026, 5:37:37 PM",
6+
"dateUpdated": "Aug 17, 2026, 11:40:00 AM",
77
"baseScore": 8.1,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",

advisories/2025/04/EUVD-2025-9524.json

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "3c00498b-7691-3e1b-9a72-54b485f418e6",
44
"description": "A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.",
55
"datePublished": "Apr 2, 2025, 11:07:43 AM",
6-
"dateUpdated": "Aug 16, 2026, 12:24:30 PM",
6+
"dateUpdated": "Aug 17, 2026, 12:29:04 PM",
77
"baseScore": 4.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
@@ -13,24 +13,24 @@
1313
"epss": 0.34,
1414
"enisaIdProduct": [
1515
{
16-
"id": "4cec0831-47a2-33c8-920c-c58a4d6a7850",
16+
"id": "7999fca7-c8f9-3311-a5da-85d393bfec7c",
1717
"product": {
18-
"name": "Red Hat OpenShift distributed tracing 3.5.1",
18+
"name": "Red Hat OpenShift distributed tracing 3.5.3",
1919
"vendor": {
2020
"name": "Red Hat"
2121
}
2222
},
23-
"product_version": "patch: rhosdt-3.5-1744028971"
23+
"product_version": "patch: rhosdt-3.5-1743162265"
2424
},
2525
{
26-
"id": "7cc79f87-bca8-3091-89b5-78668554644a",
26+
"id": "d495c522-e886-3e1c-811f-510a7b2f711c",
2727
"product": {
28-
"name": "Red Hat OpenShift distributed tracing 3.5.1",
28+
"name": "Red Hat OpenShift distributed tracing 3.5.3",
2929
"vendor": {
3030
"name": "Red Hat"
3131
}
3232
},
33-
"product_version": "patch: rhosdt-3.5-1743162265"
33+
"product_version": "patch: rhosdt-3.5-1744028971"
3434
}
3535
],
3636
"enisaIdVendor": [

0 commit comments

Comments
 (0)