Skip to content

Commit 0ef5128

Browse files
Sync EUVD catalog: Fri Apr 17 00:40:58 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 65cde70 commit 0ef5128

153 files changed

Lines changed: 5429 additions & 142 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2024/05/EUVD-2024-1469.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "9e0c8f1f-bde2-3323-89f4-371cbd10e814",
44
"description": "A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.",
55
"datePublished": "May 9, 2024, 2:57:21 PM",
6-
"dateUpdated": "Feb 3, 2026, 9:31:25 PM",
6+
"dateUpdated": "Apr 16, 2026, 1:44:01 AM",
77
"baseScore": 8.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
10-
"references": "https://nvd.nist.gov/vuln/detail/CVE-2024-3727\nhttps://github.com/containers/image/commit/132678b47bae29c710589012668cb85859d88385\nhttps://github.com/containers/image/commit/e8948046055060605bd68289d406ce149590c33a\nhttps://access.redhat.com/errata/RHSA-2024:9098\nhttps://access.redhat.com/errata/RHSA-2024:9102\nhttps://access.redhat.com/errata/RHSA-2024:9960\nhttps://access.redhat.com/security/cve/CVE-2024-3727\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2274767\nhttps://github.com/advisories/GHSA-6wvf-f2vw-3425\nhttps://github.com/containers/image\nhttps://github.com/containers/image/releases/tag/v5.29.3\nhttps://github.com/containers/image/releases/tag/v5.30.1\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4HEYS34N55G7NOQZKNEXZKQVNDGEICCD\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6B37TXOKTKDBE2V26X2NSP7JKNMZOFVP\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CYT3D2P3OJKISNFKOOHGY6HCUCQZYAVR\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DLND3YDQQRWVRIUPL2G5UKXP5L3VSBBT\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DTOMYERG5ND4QFDHC4ZSGCED3T3ESRSC\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FBZQ2ZRMFEUQ35235B2HWPSXGDCBZHFV\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GD2GSBQTBLYADASUBHHZV2CZPTSLIPQJ\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QFXMF3VVKIZN7ZMB7PKZCSWV6MOMTGMQ\nhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFVSMR7TNLO2KPWJSW4CF64C2QMQXCIN\nhttps://access.redhat.com/errata/RHSA-2024:0045\nhttps://access.redhat.com/errata/RHSA-2024:3718\nhttps://access.redhat.com/errata/RHSA-2024:4159\nhttps://access.redhat.com/errata/RHSA-2024:4613\nhttps://access.redhat.com/errata/RHSA-2024:4850\nhttps://access.redhat.com/errata/RHSA-2024:4960\nhttps://access.redhat.com/errata/RHSA-2024:5258\nhttps://access.redhat.com/errata/RHSA-2024:5951\nhttps://access.redhat.com/errata/RHSA-2024:6054\nhttps://access.redhat.com/errata/RHSA-2024:6708\nhttps://access.redhat.com/errata/RHSA-2024:6818\nhttps://access.redhat.com/errata/RHSA-2024:6824\nhttps://access.redhat.com/errata/RHSA-2024:7164\nhttps://access.redhat.com/errata/RHSA-2024:7174\nhttps://access.redhat.com/errata/RHSA-2024:7182\nhttps://access.redhat.com/errata/RHSA-2024:7187\nhttps://access.redhat.com/errata/RHSA-2024:7922\nhttps://access.redhat.com/errata/RHSA-2024:7941\nhttps://access.redhat.com/errata/RHSA-2024:8260\nhttps://access.redhat.com/errata/RHSA-2024:8425\nhttps://access.redhat.com/errata/RHSA-2024:9097\nhttps://access.redhat.com/errata/RHSA-2024:6122\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2024:0045\nhttps://access.redhat.com/errata/RHSA-2024:3718\nhttps://access.redhat.com/errata/RHSA-2024:4159\nhttps://access.redhat.com/errata/RHSA-2024:4613\nhttps://access.redhat.com/errata/RHSA-2024:4850\nhttps://access.redhat.com/errata/RHSA-2024:4960\nhttps://access.redhat.com/errata/RHSA-2024:5258\nhttps://access.redhat.com/errata/RHSA-2024:5951\nhttps://access.redhat.com/errata/RHSA-2024:6054\nhttps://access.redhat.com/errata/RHSA-2024:6122\nhttps://access.redhat.com/errata/RHSA-2024:6708\nhttps://access.redhat.com/errata/RHSA-2024:6818\nhttps://access.redhat.com/errata/RHSA-2024:6824\nhttps://access.redhat.com/errata/RHSA-2024:7164\nhttps://access.redhat.com/errata/RHSA-2024:7174\nhttps://access.redhat.com/errata/RHSA-2024:7182\nhttps://access.redhat.com/errata/RHSA-2024:7187\nhttps://access.redhat.com/errata/RHSA-2024:7922\nhttps://access.redhat.com/errata/RHSA-2024:7941\nhttps://access.redhat.com/errata/RHSA-2024:8260\nhttps://access.redhat.com/errata/RHSA-2024:8425\nhttps://access.redhat.com/errata/RHSA-2024:9097\nhttps://access.redhat.com/errata/RHSA-2024:9098\nhttps://access.redhat.com/errata/RHSA-2024:9102\nhttps://access.redhat.com/errata/RHSA-2024:9960\nhttps://access.redhat.com/security/cve/CVE-2024-3727\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2274767\n",
1111
"aliases": "CVE-2024-3727\nGHSA-6wvf-f2vw-3425\n",
1212
"assigner": "redhat",
13-
"epss": 0.58,
13+
"epss": 0.56,
1414
"enisaIdProduct": [
1515
{
1616
"id": "005651e3-8dbd-3dc3-a388-b2cd1cd9e102",
Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
{
2+
"id": "EUVD-2023-24764",
3+
"enisaUuid": "bbb96ff2-3179-326a-87f8-6cd26a631bea",
4+
"description": "Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity.",
5+
"datePublished": "Apr 16, 2026, 9:31:12 PM",
6+
"dateUpdated": "Apr 16, 2026, 9:31:12 PM",
7+
"baseScore": 5.6,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3016.html\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-20585\n",
11+
"aliases": "GHSA-c43c-pr38-m5g2\nCVE-2023-20585\n",
12+
"assigner": "AMD",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "114a5365-4b20-3129-ac1a-957cf0ff0428",
17+
"product": {
18+
"name": "AMD EPYC\u2122 7003 Series Processors"
19+
},
20+
"product_version": "patch: SEV FW 1.37.23"
21+
},
22+
{
23+
"id": "20a5e9c3-4608-3388-9f3d-167049f72dec",
24+
"product": {
25+
"name": "AMD EPYC\u2122 9004 Series Processors"
26+
},
27+
"product_version": "patch: SEV FW 1.37.31"
28+
},
29+
{
30+
"id": "b65c4172-8398-3222-a381-f636492758a6",
31+
"product": {
32+
"name": "AMD EPYC\u2122 Embedded 7003 Series Processors"
33+
},
34+
"product_version": "patch: EmbMilanPI-SP3 1.0.0.B"
35+
},
36+
{
37+
"id": "eff8d3f2-7db3-3796-ba64-2b2491ff0da2",
38+
"product": {
39+
"name": "AMD EPYC\u2122 Embedded 9004 Series Processors"
40+
},
41+
"product_version": "patch: EmbGenoaPI-1.0.0.A"
42+
}
43+
],
44+
"enisaIdVendor": [
45+
{
46+
"id": "5b201fd9-2993-3134-b8e5-211e6138c17b",
47+
"vendor": {
48+
"name": "AMD"
49+
}
50+
}
51+
]
52+
}
Lines changed: 108 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,108 @@
1+
{
2+
"id": "EUVD-2023-44280",
3+
"enisaUuid": "21a27178-0919-3b45-b259-142493aaf14c",
4+
"description": "In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which could lead to a complete loss of confidentiality, integrity and availability.",
5+
"datePublished": "Apr 16, 2026, 6:31:23 AM",
6+
"dateUpdated": "Apr 16, 2026, 6:31:23 AM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
10+
"references": "https://certvde.com/de/advisories/VDE-2023-020/\nhttps://festo.csaf-tp.certvde.com/.well-known/csaf/white/2023/fsa-202304.json\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-3634\n",
11+
"aliases": "GHSA-gp63-xp8x-53g4\nCVE-2023-3634\n",
12+
"assigner": "CERTVDE",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0c9cc905-94d6-31ff-9e46-6e7a51d03f9f",
17+
"product": {
18+
"name": "MSE6-E2M-5000-FB36-AGD"
19+
},
20+
"product_version": "*"
21+
},
22+
{
23+
"id": "0f0c3508-3668-3b7f-ac71-ce5dacaf71b1",
24+
"product": {
25+
"name": "MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L5-MQ1-AGD"
26+
},
27+
"product_version": "*"
28+
},
29+
{
30+
"id": "25fc7566-b58e-32fb-8b0f-dcce7cf79c5a",
31+
"product": {
32+
"name": "MSE6-C2M-5000-FB44-D-RG-BAR-AMI-AGD"
33+
},
34+
"product_version": "*"
35+
},
36+
{
37+
"id": "3c315fc6-a862-3748-9957-62b643fc8eae",
38+
"product": {
39+
"name": "MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L4-AGD"
40+
},
41+
"product_version": "*"
42+
},
43+
{
44+
"id": "5a768fc0-0759-36ae-a0d3-91cd55eb5cd9",
45+
"product": {
46+
"name": "MSE6-E2M-5000-FB13-AGD"
47+
},
48+
"product_version": "*"
49+
},
50+
{
51+
"id": "67158127-f78f-302e-a373-9e38acebdb3c",
52+
"product": {
53+
"name": "MSE6-C2M-5000-FB44-D-M-RG-BAR-AMI-AGD"
54+
},
55+
"product_version": "*"
56+
},
57+
{
58+
"id": "8658dd27-d9f1-3c1c-8265-eac47bc4453b",
59+
"product": {
60+
"name": "MSE6-E2M-5000-FB44-AGD"
61+
},
62+
"product_version": "*"
63+
},
64+
{
65+
"id": "a5b64fdf-dadd-39cd-b604-641a7db051d8",
66+
"product": {
67+
"name": "MSE6-E2M-5000-FB43-AGD"
68+
},
69+
"product_version": "*"
70+
},
71+
{
72+
"id": "d56cb853-df2b-3d53-9dfb-eba2362a9c7b",
73+
"product": {
74+
"name": "MSE6-D2M-5000-CBUS-S-RG-BAR-VCB-AGD"
75+
},
76+
"product_version": "*"
77+
},
78+
{
79+
"id": "d915e7cf-7714-318f-bfb4-95199782cf38",
80+
"product": {
81+
"name": "MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L5-AGD"
82+
},
83+
"product_version": "*"
84+
},
85+
{
86+
"id": "df6a9bf6-9d95-3b12-be0b-3f1ee114ad86",
87+
"product": {
88+
"name": "MSE6-E2M-5000-FB37-AGD"
89+
},
90+
"product_version": "*"
91+
},
92+
{
93+
"id": "ec3e0463-5882-31e5-acc4-ceb731432892",
94+
"product": {
95+
"name": "MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L4-MQ1-AGD"
96+
},
97+
"product_version": "*"
98+
}
99+
],
100+
"enisaIdVendor": [
101+
{
102+
"id": "11c85d90-bbb1-3cc6-8dc0-a5c9f9c27b43",
103+
"vendor": {
104+
"name": "Festo"
105+
}
106+
}
107+
]
108+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2023-58146",
3+
"enisaUuid": "9886c530-b2a7-3b8b-8322-185e79b32da7",
4+
"description": "In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.",
5+
"datePublished": "Apr 16, 2026, 6:31:23 AM",
6+
"dateUpdated": "Apr 16, 2026, 6:31:23 AM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
10+
"references": "https://certvde.com/de/advisories/VDE-2023-045\nhttps://wago.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-045.json\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-5872\n",
11+
"aliases": "GHSA-hjc2-4gp6-gj54\nCVE-2023-5872\n",
12+
"assigner": "CERTVDE",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "69cede35-62bb-3796-a18a-c8335ce66376",
17+
"product": {
18+
"name": "Smart Designer"
19+
},
20+
"product_version": "0.0.0 \u22642.33.1"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "53cefc64-b012-3961-9a54-186a388f4d45",
26+
"vendor": {
27+
"name": "WAGO"
28+
}
29+
}
30+
]
31+
}
Lines changed: 150 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,150 @@
1+
{
2+
"id": "EUVD-2024-27327",
3+
"enisaUuid": "656af96f-f48c-3267-9c83-497c2d1b3ae2",
4+
"description": "The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources.\n\nBy leveraging this vulnerability, an attacker can read confidential files from the file system and access limited HTTP resources reachable by the product. Additionally, the vulnerability can be exploited to perform denial of service attacks by exhausting server resources through recursive entity expansion or fetching large external resources.",
5+
"datePublished": "Apr 16, 2026, 9:31:45 AM",
6+
"dateUpdated": "Apr 16, 2026, 9:31:45 AM",
7+
"baseScore": 7.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
10+
"references": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3255/\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-2374\n",
11+
"aliases": "CVE-2024-2374\nGHSA-98jv-r7r8-3rqm\n",
12+
"assigner": "WSO2",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "04a0fde5-f676-35d9-933e-33219e70445d",
17+
"product": {
18+
"name": "WSO2 Identity Server as Key Manager"
19+
},
20+
"product_version": ""
21+
},
22+
{
23+
"id": "22eca78c-916e-3e68-a3cc-7ccdd6d20db0",
24+
"product": {
25+
"name": "WSO2 Identity Server"
26+
},
27+
"product_version": ""
28+
},
29+
{
30+
"id": "276a10a6-db50-31b9-8e12-ac4128cde26f",
31+
"product": {
32+
"name": "WSO2 Identity Server"
33+
},
34+
"product_version": "5.10.0 <5.10.0.300"
35+
},
36+
{
37+
"id": "44755d2d-d92b-3490-a29e-7837e34ec767",
38+
"product": {
39+
"name": "WSO2 Identity Server"
40+
},
41+
"product_version": "5.11.0 <5.11.0.329"
42+
},
43+
{
44+
"id": "49cf7d5b-91da-32c6-9eb5-a121a4d3df88",
45+
"product": {
46+
"name": "WSO2 Open Banking AM"
47+
},
48+
"product_version": "2.0.0 <2.0.0.328"
49+
},
50+
{
51+
"id": "5fce7df9-a5a0-3958-82b3-50d3e662990e",
52+
"product": {
53+
"name": "WSO2 API Manager"
54+
},
55+
"product_version": "3.2.0 <3.2.0.368"
56+
},
57+
{
58+
"id": "6554ff26-8ad9-39b0-813e-ac1cdd61a64c",
59+
"product": {
60+
"name": "WSO2 Identity Server"
61+
},
62+
"product_version": "6.0.0 <6.0.0.179"
63+
},
64+
{
65+
"id": "7171cf45-780f-3b34-89a8-673912def7f8",
66+
"product": {
67+
"name": "WSO2 API Manager"
68+
},
69+
"product_version": "4.2.0 <4.2.0.144"
70+
},
71+
{
72+
"id": "7cb4d565-20ac-302c-a113-fb465de34322",
73+
"product": {
74+
"name": "WSO2 API Manager"
75+
},
76+
"product_version": "3.1.0 <3.1.0.278"
77+
},
78+
{
79+
"id": "98432e2a-9a13-3970-95cc-4abcfc073cec",
80+
"product": {
81+
"name": "WSO2 API Manager"
82+
},
83+
"product_version": "4.1.0 <4.1.0.206"
84+
},
85+
{
86+
"id": "a041d121-8b6c-3f3a-a188-a7f8d51931e8",
87+
"product": {
88+
"name": "WSO2 API Manager"
89+
},
90+
"product_version": "4.3.0 <4.3.0.57"
91+
},
92+
{
93+
"id": "a4d6efa6-62ff-32be-b091-7edc862bf497",
94+
"product": {
95+
"name": "WSO2 Identity Server"
96+
},
97+
"product_version": "6.1.0 <6.1.0.136"
98+
},
99+
{
100+
"id": "af3281a9-4346-3711-adcb-f549b9920a98",
101+
"product": {
102+
"name": "WSO2 Open Banking IAM"
103+
},
104+
"product_version": ""
105+
},
106+
{
107+
"id": "be2cd4ee-878e-3688-9cd9-361ce64d73de",
108+
"product": {
109+
"name": "WSO2 API Manager"
110+
},
111+
"product_version": ""
112+
},
113+
{
114+
"id": "c0861114-19e7-313a-b856-08a12a4e35b0",
115+
"product": {
116+
"name": "WSO2 Open Banking IAM"
117+
},
118+
"product_version": "2.0.0 <2.0.0.348"
119+
},
120+
{
121+
"id": "dd1d6641-4437-35c0-8181-44452172ae23",
122+
"product": {
123+
"name": "WSO2 Open Banking AM"
124+
},
125+
"product_version": ""
126+
},
127+
{
128+
"id": "facba0e3-7892-359c-ba4b-db7afa862ed0",
129+
"product": {
130+
"name": "WSO2 API Manager"
131+
},
132+
"product_version": "4.0.0 <4.0.0.280"
133+
},
134+
{
135+
"id": "fdb882f4-89d4-3fc5-b31e-07bd521d621a",
136+
"product": {
137+
"name": "WSO2 Identity Server as Key Manager"
138+
},
139+
"product_version": "5.10.0 <5.10.0.296"
140+
}
141+
],
142+
"enisaIdVendor": [
143+
{
144+
"id": "507a82fd-8e1e-348d-aa21-194739bf4af7",
145+
"vendor": {
146+
"name": "WSO2"
147+
}
148+
}
149+
]
150+
}

0 commit comments

Comments
 (0)