Skip to content

Commit c4e6ef3

Browse files
Sync EUVD catalog: Sun Jun 7 00:59:13 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent b0f2052 commit c4e6ef3

251 files changed

Lines changed: 6531 additions & 657 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2023/12/EUVD-2023-58902.json

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "ccc98e9b-c024-317b-be9e-561894a8caea",
44
"description": "An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.",
55
"datePublished": "Dec 15, 2023, 4:02:40 PM",
6-
"dateUpdated": "Apr 18, 2026, 4:06:06 AM",
6+
"dateUpdated": "Jun 6, 2026, 4:06:08 AM",
77
"baseScore": 7.4,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
@@ -15,21 +15,30 @@
1515
{
1616
"id": "6a3dde43-c234-3334-a270-07486a3f21f2",
1717
"product": {
18-
"name": "GitLab"
18+
"name": "GitLab",
19+
"vendor": {
20+
"name": "GitLab"
21+
}
1922
},
2023
"product_version": "16.6 <16.6.2"
2124
},
2225
{
2326
"id": "d4060106-68df-38b8-9a5c-03d793ec66a2",
2427
"product": {
25-
"name": "GitLab"
28+
"name": "GitLab",
29+
"vendor": {
30+
"name": "GitLab"
31+
}
2632
},
2733
"product_version": "11.6 <16.4.4"
2834
},
2935
{
3036
"id": "d7b71548-80be-3184-aa69-a40fa12a400f",
3137
"product": {
32-
"name": "GitLab"
38+
"name": "GitLab",
39+
"vendor": {
40+
"name": "GitLab"
41+
}
3342
},
3443
"product_version": "16.5 <16.5.4"
3544
}

advisories/2025/02/EUVD-2025-4363.json

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,24 @@
11
{
22
"id": "EUVD-2025-4363",
33
"enisaUuid": "58c1b5f0-45a4-32c8-b111-103e8649b1dc",
4-
"description": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tekrom Technology T-Soft E-Commerce allows Cross-Site Scripting (XSS).This issue affects T-Soft E-Commerce: before v5.",
4+
"description": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tekrom Technology T-Soft E-Commerce allows Cross-Site Scripting (XSS).\n\nThis issue affects T-Soft E-Commerce: before v5.",
55
"datePublished": "Feb 24, 2025, 1:43:48 PM",
6-
"dateUpdated": "Feb 24, 2025, 4:59:24 PM",
6+
"dateUpdated": "Jun 6, 2026, 7:36:42 AM",
77
"baseScore": 4.7,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
10-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2025-0545\nhttps://www.usom.gov.tr/bildirim/tr-25-0041\n",
10+
"references": "https://www.usom.gov.tr/bildirim/tr-25-0041\nhttps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0041\n",
1111
"aliases": "CVE-2025-0545\nGHSA-p555-fgxh-v7q6\n",
1212
"assigner": "TR-CERT",
13-
"epss": 0.14,
13+
"epss": 0.09,
1414
"enisaIdProduct": [
1515
{
1616
"id": "668a5044-40b6-3211-8e7b-8239551af8a4",
1717
"product": {
18-
"name": "T-Soft E-Commerce"
18+
"name": "T-Soft E-Commerce",
19+
"vendor": {
20+
"name": "Tekrom Technology Inc."
21+
}
1922
},
2023
"product_version": "0 <v5"
2124
}

advisories/2025/02/EUVD-2025-4799.json

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,24 @@
11
{
22
"id": "EUVD-2025-4799",
33
"enisaUuid": "1893d5bb-9853-3e23-900e-c24e328d765c",
4-
"description": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010.",
4+
"description": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.\n\nThis issue affects Liman MYS: before 2.1.1 - 1010.",
55
"datePublished": "Feb 18, 2025, 1:48:29 PM",
6-
"dateUpdated": "Feb 20, 2025, 11:20:46 AM",
6+
"dateUpdated": "Jun 6, 2026, 6:56:01 AM",
77
"baseScore": 4.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:L",
10-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2025-1269\nhttps://github.com/limanmys/core/releases/tag/release.master.1010\nhttps://www.usom.gov.tr/bildirim/tr-25-0038\n",
10+
"references": "https://github.com/limanmys/core/releases/tag/release.master.1010\nhttps://www.usom.gov.tr/bildirim/tr-25-0038\nhttps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0038\n",
1111
"aliases": "CVE-2025-1269\nGHSA-jhqw-cq3q-2p2g\n",
1212
"assigner": "TR-CERT",
1313
"epss": 0.04,
1414
"enisaIdProduct": [
1515
{
1616
"id": "7b965c3b-3462-3862-9ffd-43b255b73959",
1717
"product": {
18-
"name": "Liman MYS"
18+
"name": "Liman MYS",
19+
"vendor": {
20+
"name": "HAVELSAN"
21+
}
1922
},
2023
"product_version": "0 <2.1.1 - 1010"
2124
}

advisories/2025/02/EUVD-2025-4800.json

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,24 @@
11
{
22
"id": "EUVD-2025-4800",
33
"enisaUuid": "0eb259bd-931f-379f-a2cd-f70320fb5d25",
4-
"description": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.",
4+
"description": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.\n\nThis issue affects KLog Server: before 3.1.1.",
55
"datePublished": "Feb 18, 2025, 11:30:15 AM",
6-
"dateUpdated": "Feb 18, 2025, 2:14:39 PM",
6+
"dateUpdated": "Jun 6, 2026, 6:58:22 AM",
77
"baseScore": 5.7,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
10-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2025-1035\nhttps://www.klogserver.com/surum-notlari/3-1-1\nhttps://www.usom.gov.tr/bildirim/tr-25-0037\nhttps://www.klogserver.com/surum-notlari/3-1-1/\n",
10+
"references": "https://www.usom.gov.tr/bildirim/tr-25-0037\nhttps://www.klogserver.com/surum-notlari/3-1-1/\nhttps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0037\n",
1111
"aliases": "GHSA-ppfw-4w98-jv98\nCVE-2025-1035\n",
1212
"assigner": "TR-CERT",
13-
"epss": 61.97,
13+
"epss": 70.42,
1414
"enisaIdProduct": [
1515
{
1616
"id": "ac978418-fa0e-301b-b0a5-52f5dd8547ff",
1717
"product": {
18-
"name": "KLog Server"
18+
"name": "KLog Server",
19+
"vendor": {
20+
"name": "Komtera Technolgies"
21+
}
1922
},
2023
"product_version": "0 <3.1.1"
2124
}

advisories/2025/03/EUVD-2025-6183.json

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,24 @@
11
{
22
"id": "EUVD-2025-6183",
33
"enisaUuid": "7511e87f-1ec4-38c3-a4fb-bed6414feaa2",
4-
"description": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AtaksAPP Reservation Management System allows Cross-Site Scripting (XSS).This issue affects Reservation Management System: before 4.2.3.",
4+
"description": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AtaksAPP Reservation Management System allows Cross-Site Scripting (XSS).\n\nThis issue affects Reservation Management System: before 4.2.3.",
55
"datePublished": "Mar 6, 2025, 1:09:06 PM",
6-
"dateUpdated": "Mar 6, 2025, 3:50:52 PM",
6+
"dateUpdated": "Jun 6, 2026, 7:10:51 AM",
77
"baseScore": 4.7,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
10-
"references": "https://www.usom.gov.tr/bildirim/tr-25-0059\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-0877\n",
10+
"references": "https://www.usom.gov.tr/bildirim/tr-25-0059\nhttps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0059\n",
1111
"aliases": "CVE-2025-0877\nGHSA-w896-hhvv-gm4g\n",
1212
"assigner": "TR-CERT",
13-
"epss": 0.12,
13+
"epss": 0.05,
1414
"enisaIdProduct": [
1515
{
1616
"id": "ce8e72db-2cc3-334d-8798-31aa6402a531",
1717
"product": {
18-
"name": "Reservation Management System"
18+
"name": "Reservation Management System",
19+
"vendor": {
20+
"name": "AtaksAPP"
21+
}
1922
},
2023
"product_version": "0 <4.2.3"
2124
}

advisories/2025/03/EUVD-2025-6806.json

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,24 @@
11
{
22
"id": "EUVD-2025-6806",
33
"enisaUuid": "6e788197-12a9-3473-ab4a-98aee2d4035d",
4-
"description": "Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring.This issue affects SecHard: before 3.3.0.20220411.",
4+
"description": "Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring.\n\nThis issue affects SecHard: before 3.3.0.20220411.",
55
"datePublished": "Mar 20, 2025, 11:55:51 AM",
6-
"dateUpdated": "Mar 21, 2025, 6:38:05 AM",
6+
"dateUpdated": "Jun 6, 2026, 6:14:52 AM",
77
"baseScore": 9.0,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
10-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2025-2311\nhttps://www.usom.gov.tr/bildirim/tr-25-0074\n",
10+
"references": "https://www.usom.gov.tr/bildirim/tr-25-0074\nhttps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0074\n",
1111
"aliases": "GHSA-cfc5-c899-6ww2\nCVE-2025-2311\n",
1212
"assigner": "TR-CERT",
13-
"epss": 0.03,
13+
"epss": 0.01,
1414
"enisaIdProduct": [
1515
{
1616
"id": "5db6bd35-24ee-3c59-b65c-b82e7f64ba8e",
1717
"product": {
18-
"name": "SecHard"
18+
"name": "SecHard",
19+
"vendor": {
20+
"name": "Sechard Information Technologies"
21+
}
1922
},
2023
"product_version": "0 <3.3.0.20220411"
2124
}

advisories/2025/03/EUVD-2025-7131.json

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,24 @@
11
{
22
"id": "EUVD-2025-7131",
33
"enisaUuid": "85cfe9c8-b240-3db9-b8f3-97688a358f76",
4-
"description": "Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse.This issue affects Coslat Hotspot: before 6.26.0.R.20250227.",
4+
"description": "Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse.\n\nThis issue affects Coslat Hotspot: before 6.26.0.R.20250227.",
55
"datePublished": "Mar 20, 2025, 1:30:04 PM",
6-
"dateUpdated": "Mar 20, 2025, 2:12:29 PM",
6+
"dateUpdated": "Jun 6, 2026, 6:50:44 AM",
77
"baseScore": 6.5,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
10-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2025-1496\nhttps://www.coslat.com/tr/blog/28-02-2025-guncelleme\nhttps://www.usom.gov.tr/bildirim/tr-25-0075\n",
10+
"references": "https://www.coslat.com/tr/blog/28-02-2025-guncelleme\nhttps://www.usom.gov.tr/bildirim/tr-25-0075\nhttps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0075\n",
1111
"aliases": "CVE-2025-1496\nGHSA-v4v8-93mw-cjfm\n",
1212
"assigner": "TR-CERT",
13-
"epss": 0.08,
13+
"epss": 0.16,
1414
"enisaIdProduct": [
1515
{
1616
"id": "fac98625-ee60-3ef8-8e35-34e4d465f9f8",
1717
"product": {
18-
"name": "Coslat Hotspot"
18+
"name": "Coslat Hotspot",
19+
"vendor": {
20+
"name": "BG-TEK"
21+
}
1922
},
2023
"product_version": "0 <6.26.0.r.20250227"
2124
}

advisories/2025/05/EUVD-2025-13110.json

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,24 @@
11
{
22
"id": "EUVD-2025-13110",
33
"enisaUuid": "06b03f47-47b5-373f-ba11-5de94ad081f3",
4-
"description": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis Informatics SambaBox allows Cross-Site Scripting (XSS).This issue affects SambaBox: before 5.1.",
4+
"description": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis Informatics SambaBox allows Cross-Site Scripting (XSS).\n\nThis issue affects SambaBox: before 5.1.",
55
"datePublished": "May 2, 2025, 11:30:10 AM",
6-
"dateUpdated": "Sep 12, 2025, 7:15:36 AM",
6+
"dateUpdated": "Jun 6, 2026, 5:49:19 AM",
77
"baseScore": 6.1,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
10-
"references": "https://www.usom.gov.tr/bildirim/tr-25-0101\nhttps://sambabox.io/2025/04/14/version-5-1/\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2488\n",
10+
"references": "https://www.usom.gov.tr/bildirim/tr-25-0101\nhttps://sambabox.io/2025/04/14/version-5-1/\nhttps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0101\n",
1111
"aliases": "GHSA-5m4f-q4wf-8492\nCVE-2025-2488\n",
1212
"assigner": "TR-CERT",
1313
"epss": 0.17,
1414
"enisaIdProduct": [
1515
{
1616
"id": "a4f7e117-0c57-343c-b9f8-329a0195e8e8",
1717
"product": {
18-
"name": "SambaBox"
18+
"name": "SambaBox",
19+
"vendor": {
20+
"name": "Profelis Information and Consulting Trade and Industry Limited Company"
21+
}
1922
},
2023
"product_version": "0 <5.1"
2124
}

advisories/2025/05/EUVD-2025-13111.json

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,24 @@
11
{
22
"id": "EUVD-2025-13111",
33
"enisaUuid": "16f6040c-1a1f-3c53-844d-1982b8bd19a4",
4-
"description": "Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection.This issue affects SambaBox: before 5.1.",
4+
"description": "Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection.\n\nThis issue affects SambaBox: before 5.1.",
55
"datePublished": "May 2, 2025, 11:27:49 AM",
6-
"dateUpdated": "Sep 29, 2025, 5:57:26 PM",
6+
"dateUpdated": "Jun 6, 2026, 5:51:42 AM",
77
"baseScore": 9.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
10-
"references": "https://www.usom.gov.tr/bildirim/tr-25-0101\nhttps://sambabox.io/2025/04/14/version-5-1/\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2421\n",
10+
"references": "https://www.usom.gov.tr/bildirim/tr-25-0101\nhttps://sambabox.io/2025/04/14/version-5-1/\nhttps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0101\n",
1111
"aliases": "CVE-2025-2421\nGHSA-wwmj-wfcr-vx7r\n",
1212
"assigner": "TR-CERT",
13-
"epss": 0.38,
13+
"epss": 0.36,
1414
"enisaIdProduct": [
1515
{
1616
"id": "d896c116-d4d2-3614-9a52-8fde44f21dd0",
1717
"product": {
18-
"name": "SambaBox"
18+
"name": "SambaBox",
19+
"vendor": {
20+
"name": "Profelis Information and Consulting Trade and Industry Limited Company"
21+
}
1922
},
2023
"product_version": "0 <5.1"
2124
}

advisories/2025/05/EUVD-2025-13112.json

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,24 @@
11
{
22
"id": "EUVD-2025-13112",
33
"enisaUuid": "914757e3-9218-3f67-8a7e-d490ca323ceb",
4-
"description": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Informatics Library Automation System allows Reflected XSS.This issue affects Library Automation System: before 21.6.",
4+
"description": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Informatics Library Automation System allows Reflected XSS.\n\nThis issue affects Library Automation System: before 21.6.",
55
"datePublished": "May 2, 2025, 10:59:41 AM",
6-
"dateUpdated": "Sep 12, 2025, 7:12:30 AM",
6+
"dateUpdated": "Jun 6, 2026, 6:54:30 AM",
77
"baseScore": 6.1,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
10-
"references": "https://www.usom.gov.tr/bildirim/tr-25-0100\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-1301\n",
10+
"references": "https://www.usom.gov.tr/bildirim/tr-25-0100\nhttps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0100\n",
1111
"aliases": "CVE-2025-1301\nGHSA-6cgp-c2gm-8g7j\n",
1212
"assigner": "TR-CERT",
1313
"epss": 0.17,
1414
"enisaIdProduct": [
1515
{
1616
"id": "67b3bb1a-f394-3cc4-9233-94e7e21127f8",
1717
"product": {
18-
"name": "Library Automation System"
18+
"name": "Library Automation System",
19+
"vendor": {
20+
"name": "Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc."
21+
}
1922
},
2023
"product_version": "0 <21.6"
2124
}

0 commit comments

Comments
 (0)