EUVD Bot

@EUVD_Bot
25 Followers
1 Following
2.3K Posts

πŸ›‘οΈ Unofficial bot posting new entries from the EU Vulnerability Database (EUVD).

πŸ”” Stay updated on the latest security vulnerabilities.
πŸ€– Automated β€’ Not affiliated with ENISA or the EU

#InfoSec #Cybersecurity #Vulnerabilities #EUVD

Maintainerhttps://infosec.exchange/@moltenbit

🚨 EUVD-2025-205451

πŸ“Š Score: 9.3/10 (CVSS v3.1)
πŸ“¦ Product: apidoc-core
🏒 Vendor: apiDoc
πŸ“… Updated: 2025-12-26

πŸ“ Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the β€œdefine” property processed by the application, poten...

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205451

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2025-205450

πŸ“Š Score: 6.5/10 (CVSS v3.1)
πŸ“… Updated: 2025-12-26

πŸ“ An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205450

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2025-205449

πŸ“Š Score: 7.5/10 (CVSS v3.1)
πŸ“… Updated: 2025-12-26

πŸ“ Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading...

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205449

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2024-26718

πŸ“Š Score: 6.2/10 (CVSS v3.1)
πŸ“… Updated: 2025-12-26

πŸ“ An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the Sciter video rendering function.

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-26718

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2024-55363

πŸ“Š Score: n/a
πŸ“… Updated: 2025-12-26

πŸ“ Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55363

#cybersecurity #infosec #euvd #cve #vulnerability

🚨 EUVD-2025-205448

πŸ“Š Score: 6.5/10 (CVSS v3.1)
πŸ“… Updated: 2025-12-26

πŸ“ Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205448

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2024-55362

πŸ“Š Score: 7.5/10 (CVSS v3.1)
πŸ“… Updated: 2025-12-26

πŸ“ A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55362

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2024-3456

πŸ“Š Score: 7.5/10 (CVSS v3.1)
πŸ“¦ Product: rpgp
🏒 Vendor: rpgp
πŸ“… Published: 2024-12-05 | Updated: 2025-12-26

πŸ“ rPGP Panics on Malformed Untrusted Input

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-3456

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2025-203961

πŸ“Š Score: 5.5/10 (CVSS v3.1)
πŸ“¦ Product: macOS
🏒 Vendor: Apple
πŸ“… Published: 2025-12-17 | Updated: 2025-12-26

πŸ“ A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-203961

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2025-37718

πŸ“Š Score: 5.5/10 (CVSS v3.1)
πŸ“¦ Product: macOS, macOS, macOS
🏒 Vendor: Apple
πŸ“… Published: 2025-11-04 | Updated: 2025-12-26

πŸ“ A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app may bypass Gatekeeper checks.

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-37718

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database