EQSTLab
12 записей с упоминанием · 12 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2026-101062Эксплойта нет | Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registrationobot-platform · obot · CWE-863 | Высокая8,7 | — | 0,3 % | 2 дня назад |
28Наблюдать | CVE-2026-101059Эксплойта нет | utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypassuniversal-tool-calling-protocol · python-utcp · CWE-918 | Высокая7,1 | — | 0,2 % | 2 дня назад |
28Наблюдать | CVE-2026-101058Эксплойта нет | python-utcp before 1.1.12 SSRF via Remote HTTP Manualuniversal-tool-calling-protocol · python-utcp · CWE-918 | Высокая7,1 | — | 0,2 % | 2 дня назад |
28Наблюдать | CVE-2026-90933Эксплойта нет | laradashboard through 1.2.2 Missing Authorization via License APIlaradashboard · laradashboard · CWE-862 | Высокая7,1 | — | 0,3 % | 14 сент. 2026 г. |
30Наблюдать | CVE-2026-85124Эксплойта нет | @fastify/http-proxy vulnerable to prefix escape via backslash dot-segmentsfastify · fastify\/http-proxy · CWE-22 | Высокая7,5 | — | 0,7 % | 3 сент. 2026 г. |
30Наблюдать | CVE-2026-75759Эксплойта нет | Encrypted ID token or JARM response accepted without a nested signature in erlef oidccerlef · oidcc · CWE-347 | Высокая7,6 | — | 0,2 % | 29 авг. 2026 г. |
32Наблюдать | CVE-2026-16231Эксплойта нет | hbs vulnerable to XSS via registerAsyncHelper output-escaping bypasshbs project · hbs · CWE-79 | Высокая8,1 | — | 0,2 % | 25 авг. 2026 г. |
30Наблюдать | CVE-2026-65633Эксплойта нет | Purpose-limited JWT accepted as full bearer authentication in AshAuthenticationteam-alembic · ash_authentication · CWE-287 | Высокая7,6 | — | 0,6 % | 25 авг. 2026 г. |
33Наблюдать | CVE-2026-76225Эксплойта нет | ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSVarcadedata · arcadedb · CWE-918 | Высокая8,3 | — | 0,4 % | 19 авг. 2026 г. |
36Наблюдать | CVE-2026-18248Эксплойта нет | @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event headerfastify · fastify\/aws-lambda · CWE-345 | Критическая9,1 | — | 0,4 % | 3 авг. 2026 г. |
35Наблюдать | CVE-2026-64623Эксплойта нет | Network-AI before 5.13.4 Cryptographic Signature Verification Bypassjovancoding · network-ai · CWE-347 | Высокая8,8 | — | 0,3 % | 20 июл. 2026 г. |
37Наблюдать | CVE-2026-62241Эксплойта нет | clawvet < 0.7.5 Hard-coded JWT Secret Session Forgerymohibshaikh · clawvet · CWE-306 | Критическая9,3 | — | 0,7 % | 16 июл. 2026 г. |
- CVE-2026-10106234Наблюдать
Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %obot-platform · obot2 дня назад
- CVE-2026-10105928Наблюдать
utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %universal-tool-calling-protocol · python-utcp2 дня назад
- CVE-2026-10105828Наблюдать
python-utcp before 1.1.12 SSRF via Remote HTTP Manual
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %universal-tool-calling-protocol · python-utcp2 дня назад
- CVE-2026-9093328Наблюдать
laradashboard through 1.2.2 Missing Authorization via License API
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %laradashboard · laradashboard14 сент. 2026 г.
- CVE-2026-8512430Наблюдать
@fastify/http-proxy vulnerable to prefix escape via backslash dot-segments
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %fastify · fastify\/http-proxy3 сент. 2026 г.
- CVE-2026-7575930Наблюдать
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %erlef · oidcc29 авг. 2026 г.
- CVE-2026-1623132Наблюдать
hbs vulnerable to XSS via registerAsyncHelper output-escaping bypass
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %hbs project · hbs25 авг. 2026 г.
- CVE-2026-6563330Наблюдать
Purpose-limited JWT accepted as full bearer authentication in AshAuthentication
ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %team-alembic · ash_authentication25 авг. 2026 г.
- CVE-2026-7622533Наблюдать
ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %arcadedata · arcadedb19 авг. 2026 г.
- CVE-2026-1824836Наблюдать
@fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %fastify · fastify\/aws-lambda3 авг. 2026 г.
- CVE-2026-6462335Наблюдать
Network-AI before 5.13.4 Cryptographic Signature Verification Bypass
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %jovancoding · network-ai20 июл. 2026 г.
- CVE-2026-6224137Наблюдать
clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %mohibshaikh · clawvet16 июл. 2026 г.