container native virtualization kayıtları
container native virtualization üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %85,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-7374İstismar yok | Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerabilityred hat · red hat container native virtualization 4.12 · CWE-59 | Kritik9,9 | — | %0,8 | 26 May 2026 |
37İzleyin | CVE-2026-44990İstismar yok | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`apostrophecms · sanitize-html · CWE-79 | Kritik9,3 | — | %0,7 | 12 Haz 2026 |
36İzleyin | CVE-2026-9277Kavram kanıtı | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Kritik9,2 | — | %1,0 | 22 May 2026 |
34İzleyin | CVE-2026-35469İstismar yok | SpdyStream: DOS on CRImoby · spdystream · CWE-770 | Yüksek8,7 | — | %0,8 | 16 Nis 2026 |
34İzleyin | CVE-2025-14459İstismar yok | Virt-cdi-controller: unauthorized pvc cloning via dataimportcronred hat · rhel-9-cnv-4.19 · CWE-639 | Yüksek8,5 | — | %0,4 | 26 Oca 2026 |
30İzleyin | CVE-2026-9804İstismar yok | Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file readred hat · red hat container native virtualization 4.17 · CWE-59 | Yüksek7,7 | — | %0,7 | 28 May 2026 |
30İzleyin | CVE-2024-52011Kavram kanıtı | launch-editor vulnerable to command injection via the crafted request on Windowsvitejs · launch-editor · CWE-77 | Yüksek7,5 | — | %0,5 | 1 Haz 2026 |
- CVE-2026-737439İzleyin
Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
KritikCVSS 9,9İstismar yokEPSS %1red hat · red hat container native virtualization 4.1226 May 2026
- CVE-2026-4499037İzleyin
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
KritikCVSS 9,3İstismar yokEPSS %1apostrophecms · sanitize-html12 Haz 2026
- CVE-2026-927736İzleyin
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
KritikCVSS 9,2Kavram kanıtıEPSS %122 May 2026
- CVE-2026-3546934İzleyin
SpdyStream: DOS on CRI
YüksekCVSS 8,7İstismar yokEPSS %1moby · spdystream16 Nis 2026
- CVE-2025-1445934İzleyin
Virt-cdi-controller: unauthorized pvc cloning via dataimportcron
YüksekCVSS 8,5İstismar yokEPSS %0red hat · rhel-9-cnv-4.1926 Oca 2026
- CVE-2026-980430İzleyin
Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read
YüksekCVSS 7,7İstismar yokEPSS %1red hat · red hat container native virtualization 4.1728 May 2026
- CVE-2024-5201130İzleyin
launch-editor vulnerable to command injection via the crafted request on Windows
YüksekCVSS 7,5Kavram kanıtıEPSS %1vitejs · launch-editor1 Haz 2026