Skip to content

Commit db903a3

Browse files
Sync EUVD catalog: Tue Aug 25 00:15:34 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 064e00e commit db903a3

2,330 files changed

Lines changed: 29083 additions & 3352 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2023/06/EUVD-2023-43944.json

Lines changed: 78 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -2,21 +2,92 @@
22
"id": "EUVD-2023-43944",
33
"enisaUuid": "0c5d6fad-9420-3af7-b997-b6e0bd37411a",
44
"description": "An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.",
5-
"datePublished": "Jun 16, 2023, 9:30:26 PM",
6-
"dateUpdated": "Apr 4, 2024, 4:55:18 AM",
5+
"datePublished": "Jun 16, 2023, 12:00:00 AM",
6+
"dateUpdated": "Aug 24, 2026, 2:27:07 PM",
77
"baseScore": 7.1,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
10-
"references": "https://lore.kernel.org/lkml/1682238502-1892-1-git-send-email-yangpc@wangsu.com/T/\nhttps://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.2\nhttps://www.debian.org/security/2023/dsa-5448\nhttps://lists.debian.org/debian-lts-announce/2023/07/msg00030.html\nhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=43ec16f1450f4936025a9bdf1a273affdb9732c1\nhttps://www.debian.org/security/2023/dsa-5480\nhttps://security.netapp.com/advisory/ntap-20230824-0006/\nhttps://lists.debian.org/debian-lts-announce/2023/10/msg00027.html\nhttps://lore.kernel.org/lkml/1682238502-1892-1-git-send-email-yangpc%40wangsu.com/T/\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-3268\n",
10+
"references": "https://lore.kernel.org/lkml/1682238502-1892-1-git-send-email-yangpc%40wangsu.com/T/\nhttps://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.2\nhttps://www.debian.org/security/2023/dsa-5448\nhttps://lists.debian.org/debian-lts-announce/2023/07/msg00030.html\nhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=43ec16f1450f4936025a9bdf1a273affdb9732c1\nhttps://www.debian.org/security/2023/dsa-5480\nhttps://security.netapp.com/advisory/ntap-20230824-0006/\nhttps://lists.debian.org/debian-lts-announce/2023/10/msg00027.html\n",
1111
"aliases": "GHSA-r2p2-3cx2-xc3r\nCVE-2023-3268\n",
1212
"assigner": "redhat",
13-
"epss": 0.01,
14-
"enisaIdProduct": [],
13+
"epss": 0.47,
14+
"enisaIdProduct": [
15+
{
16+
"id": "42f3091a-895b-380f-86ad-4cfe3dcdecae",
17+
"product": {
18+
"name": "Kernel",
19+
"vendor": {
20+
"name": "Linux"
21+
}
22+
},
23+
"product_version": "6.2 <6.2.15"
24+
},
25+
{
26+
"id": "6cb7f087-2d7f-3bca-9629-3fd6c6f7c494",
27+
"product": {
28+
"name": "Kernel",
29+
"vendor": {
30+
"name": "Linux"
31+
}
32+
},
33+
"product_version": "2.6.22 <4.19.283"
34+
},
35+
{
36+
"id": "71d36bb3-9bec-34f2-a283-88ba6cd8207e",
37+
"product": {
38+
"name": "Kernel",
39+
"vendor": {
40+
"name": "Linux"
41+
}
42+
},
43+
"product_version": "5.5 <5.10.180"
44+
},
45+
{
46+
"id": "a8a0dff3-6f3c-3b28-92e5-4001b1c05b43",
47+
"product": {
48+
"name": "Kernel",
49+
"vendor": {
50+
"name": "Linux"
51+
}
52+
},
53+
"product_version": "5.16 <6.1.28"
54+
},
55+
{
56+
"id": "cc6a8a39-e5f3-3089-ab5f-5abab3587c7f",
57+
"product": {
58+
"name": "Kernel",
59+
"vendor": {
60+
"name": "Linux"
61+
}
62+
},
63+
"product_version": "6.3 <6.3.2"
64+
},
65+
{
66+
"id": "ebb8dabc-5e66-36fa-91f2-1b78e1d1fa00",
67+
"product": {
68+
"name": "Kernel",
69+
"vendor": {
70+
"name": "Linux"
71+
}
72+
},
73+
"product_version": "4.20 <5.4.243"
74+
},
75+
{
76+
"id": "ec84d79b-3945-3d8c-a62c-9d28ae2d1ff9",
77+
"product": {
78+
"name": "Kernel",
79+
"vendor": {
80+
"name": "Linux"
81+
}
82+
},
83+
"product_version": "5.11 <5.15.111"
84+
}
85+
],
1586
"enisaIdVendor": [
1687
{
17-
"id": "aed50e8e-94b8-3039-865e-3fac6c49a9d7",
88+
"id": "c978635c-f59c-3cae-a040-1ddbc2968d84",
1889
"vendor": {
19-
"name": "n/a"
90+
"name": "Linux"
2091
}
2192
}
2293
]

advisories/2024/01/EUVD-2024-0459.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "4e9c3427-0aff-3862-a918-b9f48c80d302",
44
"description": "runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem (\"attack 2\"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run (\"attack 1\"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes (\"attack 3a\" and \"attack 3b\"). runc 1.1.12 includes patches for this issue.",
55
"datePublished": "Jan 31, 2024, 9:31:14 PM",
6-
"dateUpdated": "Aug 20, 2026, 12:31:47 PM",
6+
"dateUpdated": "Aug 24, 2026, 12:06:56 PM",
77
"baseScore": 8.6,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",

advisories/2024/04/EUVD-2024-1060.json

Lines changed: 19 additions & 40 deletions
Original file line numberDiff line numberDiff line change
@@ -3,73 +3,52 @@
33
"enisaUuid": "f4cf6104-e1fd-39a6-a674-9da5c2bbca52",
44
"description": "A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.",
55
"datePublished": "Apr 26, 2024, 3:12:38 AM",
6-
"dateUpdated": "Nov 20, 2025, 7:17:45 AM",
6+
"dateUpdated": "Aug 24, 2026, 2:00:29 PM",
77
"baseScore": 7.2,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
10-
"references": "https://github.com/cri-o/cri-o/security/advisories/GHSA-2cgq-h8xw-2v5j\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-3154\nhttps://github.com/opencontainers/runc/pull/4217\nhttps://access.redhat.com/security/cve/CVE-2024-3154\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2272532\nhttps://github.com/cri-o/cri-o\nhttps://github.com/opencontainers/runtime-spec/blob/main/features.md#unsafe-annotations-in-configjson\nhttps://access.redhat.com/errata/RHSA-2024:2669\nhttps://access.redhat.com/errata/RHSA-2024:2672\nhttps://access.redhat.com/errata/RHSA-2024:2784\nhttps://access.redhat.com/errata/RHSA-2024:3496\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2024:2669\nhttps://access.redhat.com/errata/RHSA-2024:2672\nhttps://access.redhat.com/errata/RHSA-2024:2784\nhttps://access.redhat.com/errata/RHSA-2024:3496\nhttps://access.redhat.com/security/cve/CVE-2024-3154\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2272532\nhttps://github.com/cri-o/cri-o/security/advisories/GHSA-2cgq-h8xw-2v5j\nhttps://github.com/opencontainers/runc/pull/4217\nhttps://github.com/opencontainers/runtime-spec/blob/main/features.md#unsafe-annotations-in-configjson\n",
1111
"aliases": "CVE-2024-3154\nGHSA-2cgq-h8xw-2v5j\n",
1212
"assigner": "redhat",
13-
"epss": 0.27,
13+
"epss": 1.42,
1414
"enisaIdProduct": [
15-
{
16-
"id": "1dc43962-aead-315c-a285-fdffbf9d8152",
17-
"product": {
18-
"name": "Red Hat OpenShift Container Platform 4.13"
19-
},
20-
"product_version": "patch: 0:1.26.5-16.2.rhaos4.13.git67e2a9d.el8"
21-
},
22-
{
23-
"id": "3dd2bcf2-6db7-3426-a20d-22d521ec2709",
24-
"product": {
25-
"name": "Red Hat OpenShift Container Platform 4.14"
26-
},
27-
"product_version": "patch: 0:1.27.6-2.rhaos4.14.gitb3bd0bf.el8"
28-
},
29-
{
30-
"id": "5d9e4d9c-da5a-3c04-a84a-b70f68ca18e7",
31-
"product": {
32-
"name": "Red Hat OpenShift Container Platform 3.11"
33-
}
34-
},
3515
{
3616
"id": "70ad9626-46c7-35b1-97c7-42c4a91ada65",
3717
"product": {
38-
"name": "Red Hat OpenShift Container Platform 4.13"
18+
"name": "Red Hat OpenShift Container Platform 4.13",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
3922
},
4023
"product_version": "patch: 0:1.26.5-16.2.rhaos4.13.git67e2a9d.el9"
4124
},
42-
{
43-
"id": "8ec16cc3-ccc8-3328-89c9-b668b8d8de2d",
44-
"product": {
45-
"name": "Red Hat OpenShift Container Platform 4"
46-
}
47-
},
4825
{
4926
"id": "bb01b0f5-09c3-38b4-bd20-1aef4aaaed0b",
5027
"product": {
51-
"name": "Red Hat OpenShift Container Platform 4.15"
28+
"name": "Red Hat OpenShift Container Platform 4.15",
29+
"vendor": {
30+
"name": "Red Hat"
31+
}
5232
},
5333
"product_version": "patch: 0:1.28.6-2.rhaos4.15.git77bbb1c.el8"
5434
},
5535
{
5636
"id": "db1be05d-c9a5-346c-8ebd-d7b73694c5ad",
5737
"product": {
58-
"name": "Red Hat OpenShift Container Platform 4.14"
38+
"name": "Red Hat OpenShift Container Platform 4.14",
39+
"vendor": {
40+
"name": "Red Hat"
41+
}
5942
},
6043
"product_version": "patch: 0:1.27.6-2.rhaos4.14.gitb3bd0bf.el9"
6144
},
62-
{
63-
"id": "e559f37e-d491-3b17-bcfe-f7ca781cf27f",
64-
"product": {
65-
"name": "Red Hat OpenShift Container Platform 4.15"
66-
},
67-
"product_version": "patch: 0:1.28.6-2.rhaos4.15.git77bbb1c.el9"
68-
},
6945
{
7046
"id": "efa058d0-3c3d-3925-9e0b-698f7c9258f1",
7147
"product": {
72-
"name": "Red Hat OpenShift Container Platform 4.12"
48+
"name": "Red Hat OpenShift Container Platform 4.12",
49+
"vendor": {
50+
"name": "Red Hat"
51+
}
7352
},
7453
"product_version": "patch: 0:1.25.5-16.2.rhaos4.12.gitcb09013.el8"
7554
}

advisories/2024/04/EUVD-2024-1102.json

Lines changed: 10 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,25 +3,24 @@
33
"enisaUuid": "1876e85d-bac9-3396-9472-12bcea0a29bb",
44
"description": "Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.",
55
"datePublished": "Apr 26, 2024, 12:00:00 AM",
6-
"dateUpdated": "Aug 2, 2024, 1:59:50 AM",
7-
"baseScore": -1.0,
8-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2024-31828\nhttps://github.com/LavaLite/cms\nhttps://jinmu1108.github.io/uncategorized/CVE-2024-31828\nhttps://jinmu1108.github.io/uncategorized/CVE-2024-31828/\n",
6+
"dateUpdated": "Aug 24, 2026, 1:32:57 PM",
7+
"baseScore": 6.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
10+
"references": "https://jinmu1108.github.io/uncategorized/CVE-2024-31828/\n",
911
"aliases": "CVE-2024-31828\nGHSA-5hcr-g32p-h74c\n",
1012
"assigner": "mitre",
11-
"epss": 0.22,
13+
"epss": 0.5,
1214
"enisaIdProduct": [
1315
{
1416
"id": "3566d81f-a000-3b99-ae0a-9e4c9053f50c",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
19-
},
20-
{
21-
"id": "c6d9a7a6-dd7b-31dd-95d9-f05e4f981ae3",
22-
"product": {
23-
"name": "n/a"
24-
}
2524
}
2625
],
2726
"enisaIdVendor": [

advisories/2024/04/EUVD-2024-19930.json

Lines changed: 8 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -2,28 +2,25 @@
22
"id": "EUVD-2024-19930",
33
"enisaUuid": "17b09b2c-aa77-3e32-ac6e-ecae15720d9b",
44
"description": "An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.",
5-
"datePublished": "Apr 25, 2024, 3:30:38 PM",
6-
"dateUpdated": "May 5, 2024, 3:30:47 AM",
5+
"datePublished": "Apr 25, 2024, 2:33:07 PM",
6+
"dateUpdated": "Aug 24, 2026, 1:36:15 PM",
77
"baseScore": 8.1,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
10-
"references": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N5HXUKUJ7SG3TK456SGUWVZ4Z5D7JKOL/\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJA7QWWZWMY4AQFR35EA7S3CFVUTOQYG/\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZJ4IG7EXMSMPHTK5ZFASCW6MHSOVZOE/\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-22373\nhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1935\n",
10+
"references": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N5HXUKUJ7SG3TK456SGUWVZ4Z5D7JKOL/\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJA7QWWZWMY4AQFR35EA7S3CFVUTOQYG/\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZJ4IG7EXMSMPHTK5ZFASCW6MHSOVZOE/\n",
1111
"aliases": "CVE-2024-22373\nGHSA-562h-465j-vfp9\n",
1212
"assigner": "talos",
13-
"epss": 0.21,
13+
"epss": 1.47,
1414
"enisaIdProduct": [
1515
{
1616
"id": "093ffbc5-df89-33ec-8fb5-c91eb4f4159d",
1717
"product": {
18-
"name": "Grassroot DICOM"
18+
"name": "Grassroot DICOM",
19+
"vendor": {
20+
"name": "Grassroot DICOM"
21+
}
1922
},
2023
"product_version": "3.0.23"
21-
},
22-
{
23-
"id": "a7ad6b2d-bbc8-36c4-8d11-5e57868161e8",
24-
"product": {
25-
"name": "Grassroot DICOM"
26-
}
2724
}
2825
],
2926
"enisaIdVendor": [

advisories/2024/04/EUVD-2024-29695.json

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,23 @@
22
"id": "EUVD-2024-29695",
33
"enisaUuid": "0f66669e-3d38-38ae-bb8e-37d97b3bed3e",
44
"description": "An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.",
5-
"datePublished": "Apr 29, 2024, 6:30:46 PM",
6-
"dateUpdated": "Jul 3, 2024, 6:37:26 PM",
7-
"baseScore": -1.0,
8-
"references": "https://liotree.github.io/2023/Ecommerce-CodeIgniter-Bootstrap.html\nhttps://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/d22b54e8915f167a135046ceb857caaf8479c4da\nhttps://gist.github.com/LioTree/4989e0f20b6a885604dd3178fa4b66b5\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-31823\n",
5+
"datePublished": "Apr 29, 2024, 12:00:00 AM",
6+
"dateUpdated": "Aug 24, 2026, 1:38:24 PM",
7+
"baseScore": 9.8,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
10+
"references": "https://liotree.github.io/2023/Ecommerce-CodeIgniter-Bootstrap.html\nhttps://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/d22b54e8915f167a135046ceb857caaf8479c4da\nhttps://gist.github.com/LioTree/4989e0f20b6a885604dd3178fa4b66b5\n",
911
"aliases": "CVE-2024-31823\nGHSA-pgmp-wx9f-mqm3\n",
1012
"assigner": "mitre",
11-
"epss": 6.19,
13+
"epss": 1.64,
1214
"enisaIdProduct": [
1315
{
1416
"id": "1388bcf5-31ea-3dc0-84ee-9fa1b053e982",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
1924
}

advisories/2024/04/EUVD-2024-34605.json

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,23 @@
22
"id": "EUVD-2024-34605",
33
"enisaUuid": "ab586932-7ead-38e7-a883-bab258cb63b9",
44
"description": "The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment().",
5-
"datePublished": "Apr 30, 2024, 12:30:35 AM",
6-
"dateUpdated": "Jul 3, 2024, 6:37:35 PM",
7-
"baseScore": -1.0,
8-
"references": "https://jira.o-ran-sc.org/browse/RIC-1047\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-34045\n",
5+
"datePublished": "Apr 29, 2024, 12:00:00 AM",
6+
"dateUpdated": "Aug 24, 2026, 1:31:57 PM",
7+
"baseScore": 7.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
10+
"references": "https://jira.o-ran-sc.org/browse/RIC-1047\n",
911
"aliases": "GHSA-c586-6hq4-j669\nCVE-2024-34045\n",
1012
"assigner": "mitre",
11-
"epss": 0.15,
13+
"epss": 0.52,
1214
"enisaIdProduct": [
1315
{
1416
"id": "60a77912-91d5-307b-a0c0-5241a7064e13",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
1924
}

advisories/2024/04/EUVD-2024-34606.json

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,23 @@
22
"id": "EUVD-2024-34606",
33
"enisaUuid": "df1321c7-79b8-3014-9e43-9f44c51a994b",
44
"description": "The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_COUNTER][ProcedureCode_id_RICsubscription]->Increment().",
5-
"datePublished": "Apr 30, 2024, 12:30:35 AM",
6-
"dateUpdated": "Nov 1, 2024, 6:31:25 PM",
7-
"baseScore": -1.0,
8-
"references": "https://jira.o-ran-sc.org/browse/RIC-1047\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-34046\n",
5+
"datePublished": "Apr 29, 2024, 12:00:00 AM",
6+
"dateUpdated": "Aug 24, 2026, 1:33:42 PM",
7+
"baseScore": 7.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
10+
"references": "https://jira.o-ran-sc.org/browse/RIC-1047\n",
911
"aliases": "GHSA-xhpx-f3qp-rwvq\nCVE-2024-34046\n",
1012
"assigner": "mitre",
11-
"epss": 0.2,
13+
"epss": 0.52,
1214
"enisaIdProduct": [
1315
{
1416
"id": "c6250b94-7b2f-3e26-8160-ca0d2ea3b562",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
1924
}

advisories/2024/05/EUVD-2024-31484.json

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,23 @@
22
"id": "EUVD-2024-31484",
33
"enisaUuid": "9f73cecf-64da-3ba6-ad28-5a83bd78398c",
44
"description": "An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.",
5-
"datePublished": "May 1, 2024, 3:30:37 PM",
6-
"dateUpdated": "Jul 3, 2024, 6:38:07 PM",
7-
"baseScore": -1.0,
8-
"references": "https://www.nagios.com/changelog/#nagios-xi\nhttps://github.com/Neo-XeD/CVE-2024-33775\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-33775\n",
5+
"datePublished": "May 1, 2024, 12:00:00 AM",
6+
"dateUpdated": "Aug 24, 2026, 1:40:52 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
10+
"references": "https://www.nagios.com/changelog/#nagios-xi\nhttps://github.com/Neo-XeD/CVE-2024-33775\n",
911
"aliases": "CVE-2024-33775\nGHSA-r3hf-mcpf-6r4f\n",
1012
"assigner": "mitre",
11-
"epss": 3.38,
13+
"epss": 1.6,
1214
"enisaIdProduct": [
1315
{
1416
"id": "3af1ef6d-00ba-3021-9099-31417eabee82",
1517
"product": {
16-
"name": "n/a"
18+
"name": "n/a",
19+
"vendor": {
20+
"name": "n/a"
21+
}
1722
},
1823
"product_version": "n/a"
1924
}

0 commit comments

Comments
 (0)