Skip to content

Commit 65cde70

Browse files
Sync EUVD catalog: Thu Apr 16 00:43:09 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 1826b96 commit 65cde70

353 files changed

Lines changed: 9468 additions & 476 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 80 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,80 @@
1+
{
2+
"id": "EUVD-2024-55542",
3+
"enisaUuid": "6d67b792-837c-34d6-8a2e-198e527fc972",
4+
"description": "Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 \r\nallows attackers to consume excessive amounts of disk space via network interface.",
5+
"datePublished": "Apr 15, 2026, 9:51:52 AM",
6+
"dateUpdated": "Apr 15, 2026, 9:51:52 AM",
7+
"baseScore": 7.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
10+
"references": "https://psirt.bosch.com/security-advisories/BOSCH-SA-162032-BT.html\n",
11+
"aliases": "CVE-2024-33618\n",
12+
"assigner": "bosch",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "1e656699-c0d4-38e1-8d86-daf4280edcd7",
17+
"product": {
18+
"name": "Bosch DIVAR IP all-in-one 5000"
19+
},
20+
"product_version": "9.0 \u226412.0.1"
21+
},
22+
{
23+
"id": "70a30347-669a-358e-9b09-c29d9bde420a",
24+
"product": {
25+
"name": "DIVAR IP all-in-one 6000"
26+
},
27+
"product_version": "11.1.1 \u226412.0.1"
28+
},
29+
{
30+
"id": "8aad694f-cec0-3da0-b418-b3b006b075d2",
31+
"product": {
32+
"name": "Bosch DIVAR IP all-in-one 7000"
33+
},
34+
"product_version": "6.0 \u226412.0.1"
35+
},
36+
{
37+
"id": "9406f634-f03c-316d-a851-0f847d9712e6",
38+
"product": {
39+
"name": "BVMS"
40+
},
41+
"product_version": "6.0 \u226412.0.1"
42+
},
43+
{
44+
"id": "9c9e1cad-7faf-3ffe-ad69-34664fd4d6be",
45+
"product": {
46+
"name": "Bosch DIVAR IP all-in-one 7000 R3"
47+
},
48+
"product_version": "10.1 \u226412.0.1"
49+
},
50+
{
51+
"id": "b7a17887-bce5-394d-ab3a-3f2951b54581",
52+
"product": {
53+
"name": "BVMS Viewer"
54+
},
55+
"product_version": "8.0 \u226412.0.1"
56+
},
57+
{
58+
"id": "e8fcada3-72a0-3b7c-a5b2-9ec1a9d0af61",
59+
"product": {
60+
"name": "Bosch DIVAR IP 7000 R2"
61+
},
62+
"product_version": "9.0 \u226412.0.1"
63+
},
64+
{
65+
"id": "fc8f3c0c-9618-3c67-9eec-df9c1af1c226",
66+
"product": {
67+
"name": "DIVAR IP all-in-one 4000"
68+
},
69+
"product_version": "11.1.1 \u226412.0.1"
70+
}
71+
],
72+
"enisaIdVendor": [
73+
{
74+
"id": "f4914173-1ae2-3245-9774-0913364f00ae",
75+
"vendor": {
76+
"name": "Bosch"
77+
}
78+
}
79+
]
80+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"id": "EUVD-2024-55543",
3+
"enisaUuid": "a77732a0-7c14-3802-b5fa-4401cc5455b9",
4+
"description": "Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field",
5+
"datePublished": "Apr 15, 2026, 3:31:43 PM",
6+
"dateUpdated": "Apr 15, 2026, 3:31:43 PM",
7+
"baseScore": 0.0,
8+
"references": "https://github.com/NietThijmen/ShoppingCart/issues/1\nhttps://github.com/Buckdray/vulnerability-research/blob/main/CVE-2024-53412/README.md\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-53412\n",
9+
"aliases": "CVE-2024-53412\nGHSA-ggmw-mjhv-75rm\n",
10+
"assigner": "mitre",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "25bb1261-1e98-3ab5-9288-dbb0fa41382f",
15+
"product": {
16+
"name": "n/a"
17+
},
18+
"product_version": "n/a"
19+
}
20+
],
21+
"enisaIdVendor": [
22+
{
23+
"id": "43311076-c7fc-3727-b896-6357cc6d4b06",
24+
"vendor": {
25+
"name": "n/a"
26+
}
27+
}
28+
]
29+
}

advisories/2026/04/EUVD-2025-209440.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
"id": "EUVD-2025-209440",
33
"enisaUuid": "c13ca6a1-e098-3562-a547-3acbfff20ed3",
44
"description": "The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. \u00a0It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. \u00a0OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption.",
5-
"datePublished": "Apr 14, 2026, 3:30:34 PM",
6-
"dateUpdated": "Apr 14, 2026, 3:30:35 PM",
5+
"datePublished": "Apr 14, 2026, 1:13:43 PM",
6+
"dateUpdated": "Apr 15, 2026, 3:58:13 AM",
77
"baseScore": 9.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:Y/V:D/RE:M/U:Red",
10-
"references": "https://community.progress.com/s/article/Unintended-Use-of-OECH1-for-Password-Secrets-Protection\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-8095\n",
10+
"references": "https://community.progress.com/s/article/Unintended-Use-of-OECH1-for-Password-Secrets-Protection\n",
1111
"aliases": "CVE-2025-8095\n",
1212
"assigner": "ProgressSoftware",
1313
"epss": 0.0,

advisories/2026/04/EUVD-2025-209453.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
"id": "EUVD-2025-209453",
33
"enisaUuid": "14668fd2-80a5-3ce8-9eb2-053b347490c7",
44
"description": "An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.8, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.8, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API",
5-
"datePublished": "Apr 14, 2026, 6:30:34 PM",
6-
"dateUpdated": "Apr 14, 2026, 6:30:34 PM",
5+
"datePublished": "Apr 14, 2026, 3:38:24 PM",
6+
"dateUpdated": "Apr 15, 2026, 3:58:25 AM",
77
"baseScore": 6.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
10-
"references": "https://fortiguard.fortinet.com/psirt/FG-IR-26-111\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-61848\n",
10+
"references": "https://fortiguard.fortinet.com/psirt/FG-IR-26-111\n",
1111
"aliases": "GHSA-p356-3hpr-4rhh\nCVE-2025-61848\n",
1212
"assigner": "fortinet",
1313
"epss": 0.0,
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"id": "EUVD-2025-209465",
3+
"enisaUuid": "467752cc-54a9-3d68-818e-f40d5fef1479",
4+
"description": "The example example_xcom\u00a0that was included in airflow documentation implemented unsafe pattern of reading value\nfrom xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary\nexecution of code on the worker. Since the UI users are already highly trusted, this is a Low severity vulnerability.\n\nIt does not affect Airflow release - example_dags are not supposed to be enabled in production environment, however\nusers following the example could replicate the bad pattern. Documentation of Airflow 3.2.0 contains version of\nthe example with improved resiliance for that case.\n\nUsers who followed that pattern are advised to adjust their implementations accordingly.",
5+
"datePublished": "Apr 15, 2026, 12:22:03 AM",
6+
"dateUpdated": "Apr 15, 2026, 3:03:33 AM",
7+
"baseScore": 0.0,
8+
"references": "https://lists.apache.org/thread/3mf4cfx070ofsnf9qy0s2v5gqb5sc2g1\nhttps://github.com/apache/airflow/pull/63200\n",
9+
"aliases": "CVE-2025-54550\n",
10+
"assigner": "apache",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "ac5d8c35-212f-30ff-b5a6-92bce1ad7fc8",
15+
"product": {
16+
"name": "Apache Airflow"
17+
},
18+
"product_version": "0 <3.2.0"
19+
}
20+
],
21+
"enisaIdVendor": [
22+
{
23+
"id": "2f38fda6-f602-3adc-8d77-3a39a13ae1be",
24+
"vendor": {
25+
"name": "Apache Software Foundation"
26+
}
27+
}
28+
]
29+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2025-209467",
3+
"enisaUuid": "d511689d-37b4-31eb-a250-09cd597fb9c2",
4+
"description": "Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher.\n\nGOSTCTR implementation unable to process more than 255 blocks correctly.\n\n\nThis issue affects BC-JAVA: from 1.59 before 1.84.",
5+
"datePublished": "Apr 15, 2026, 8:56:34 AM",
6+
"dateUpdated": "Apr 15, 2026, 10:08:52 AM",
7+
"baseScore": 9.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/RE:M/U:Red",
10+
"references": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813\nhttps://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f\nhttps://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3\n",
11+
"aliases": "CVE-2025-14813\n",
12+
"assigner": "bcorg",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "48a55827-61e8-39ee-b452-b47cbd678eb2",
17+
"product": {
18+
"name": "BC-JAVA"
19+
},
20+
"product_version": "1.59 <1.84"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "a90c4e2a-b863-344a-a89b-e8c32a57ae08",
26+
"vendor": {
27+
"name": "Legion of the Bouncy Castle Inc."
28+
}
29+
}
30+
]
31+
}
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
{
2+
"id": "EUVD-2025-209469",
3+
"enisaUuid": "3b8dd955-5ea1-3ab8-946b-874a3f35b4d0",
4+
"description": "An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Threat Intelligence functionality can perform administrative actions on it, altering the rules configuration, and/or affecting their availability.",
5+
"datePublished": "Apr 15, 2026, 8:18:05 AM",
6+
"dateUpdated": "Apr 15, 2026, 8:18:05 AM",
7+
"baseScore": 7.2,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://security.nozominetworks.com/NN-2026:1-01\n",
11+
"aliases": "CVE-2025-40897\n",
12+
"assigner": "Nozomi",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "66c3be0b-f262-3999-91b0-0a24391a0f62",
17+
"product": {
18+
"name": "Guardian"
19+
},
20+
"product_version": "0 <26.0.0"
21+
},
22+
{
23+
"id": "f066fd11-3ef9-3003-85a9-de0fd4b8b395",
24+
"product": {
25+
"name": "CMC"
26+
},
27+
"product_version": "0 <26.0.0"
28+
}
29+
],
30+
"enisaIdVendor": [
31+
{
32+
"id": "e4928b12-3c3a-3664-8187-74951b2c0047",
33+
"vendor": {
34+
"name": "Nozomi Networks"
35+
}
36+
}
37+
]
38+
}
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
{
2+
"id": "EUVD-2025-209471",
3+
"enisaUuid": "767fdb4c-4523-35e4-a651-7ac57f639e4e",
4+
"description": "A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a JavaScript payload. When the victim views the Assets or Nodes pages, the XSS executes in their browser context, allowing the attacker to perform unauthorized actions as the victim, such as modify application data, disrupt application availability, and access limited sensitive information.",
5+
"datePublished": "Apr 15, 2026, 8:18:36 AM",
6+
"dateUpdated": "Apr 15, 2026, 8:18:36 AM",
7+
"baseScore": 7.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L",
10+
"references": "https://security.nozominetworks.com/NN-2026:2-01\n",
11+
"aliases": "CVE-2025-40899\n",
12+
"assigner": "Nozomi",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "7297b2ff-8800-3c2e-a5c8-27f19055da30",
17+
"product": {
18+
"name": "CMC"
19+
},
20+
"product_version": "0 <26.0.0"
21+
},
22+
{
23+
"id": "bcf448b1-047f-3da9-b85d-57e618ba7d04",
24+
"product": {
25+
"name": "Guardian"
26+
},
27+
"product_version": "0 <26.0.0"
28+
}
29+
],
30+
"enisaIdVendor": [
31+
{
32+
"id": "9c478383-c539-35c3-9769-4502d7c6ba8a",
33+
"vendor": {
34+
"name": "Nozomi Networks"
35+
}
36+
}
37+
]
38+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2025-209473",
3+
"enisaUuid": "5b602ff4-6bad-375c-aec7-a70d00feed31",
4+
"description": "HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited information disclosure.",
5+
"datePublished": "Apr 15, 2026, 3:31:41 PM",
6+
"dateUpdated": "Apr 15, 2026, 3:31:41 PM",
7+
"baseScore": 2.9,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130007\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-52641\n",
11+
"aliases": "GHSA-p72j-qjhf-94m3\nCVE-2025-52641\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "06ec38b4-312b-3920-901c-23df38375cfe",
17+
"product": {
18+
"name": "AION"
19+
},
20+
"product_version": "2.0"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "3189a176-1729-350e-a8e6-087f26fbf572",
26+
"vendor": {
27+
"name": "HCL"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2025-209475",
3+
"enisaUuid": "a14301fa-a202-34f4-913b-4ffe90d3ef8c",
4+
"description": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions \u201calert.notifications:write\u201d or \u201calert.notifications.receivers:test\u201d that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.",
5+
"datePublished": "Apr 15, 2026, 6:31:56 PM",
6+
"dateUpdated": "Apr 15, 2026, 6:31:56 PM",
7+
"baseScore": 1.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/S:N/AU:Y",
10+
"references": "https://grafana.com/security/security-advisories/cve-2025-12141/\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-12141\n",
11+
"aliases": "CVE-2025-12141\nGHSA-pcxf-fmpx-32ph\n",
12+
"assigner": "GRAFANA",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "a867eedc-86c6-35fc-896e-d4451e9ce3cf",
17+
"product": {
18+
"name": "Grafana Alerting"
19+
},
20+
"product_version": "8.0.0 \u226412.3.0"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "ef6b41b5-df65-3943-af7d-408b28a14fb4",
26+
"vendor": {
27+
"name": "Grafana"
28+
}
29+
}
30+
]
31+
}

0 commit comments

Comments
 (0)