esm kayıtları
esm üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-65025İstismar yok | esm.sh CDN service has arbitrary file write via tarslipesm · esm.sh · CWE-22 | Kritik9,8 | — | %0,5 | 19 Kas 2025 |
38İzleyin | CVE-2025-65026İstismar yok | esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScriptesm · esm.sh · CWE-94 | Kritik9,6 | — | %0,5 | 19 Kas 2025 |
34İzleyin | CVE-2025-50180İstismar yok | esm.sh is vulnerable to full-response SSRFesm · esm.sh · CWE-918 | Yüksek8,7 | — | %0,4 | 25 Şub 2026 |
30İzleyin | CVE-2026-23644İstismar yok | esm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packagesesm · esm.sh · CWE-22 | Yüksek7,7 | — | %0,5 | 18 Oca 2026 |
30İzleyin | CVE-2026-27730İstismar yok | esm.sh has SSRF localhost/private-network bypass in `/http(s)` module routeesm · esm.sh · CWE-918 | Yüksek7,5 | — | %0,5 | 25 Şub 2026 |
- CVE-2025-6502539İzleyin
esm.sh CDN service has arbitrary file write via tarslip
KritikCVSS 9,8İstismar yokEPSS %1esm · esm.sh19 Kas 2025
- CVE-2025-6502638İzleyin
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
KritikCVSS 9,6İstismar yokEPSS %0esm · esm.sh19 Kas 2025
- CVE-2025-5018034İzleyin
esm.sh is vulnerable to full-response SSRF
YüksekCVSS 8,7İstismar yokEPSS %0esm · esm.sh25 Şub 2026
- CVE-2026-2364430İzleyin
esm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packages
YüksekCVSS 7,7İstismar yokEPSS %1esm · esm.sh18 Oca 2026
- CVE-2026-2773030İzleyin
esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route
YüksekCVSS 7,5İstismar yokEPSS %0esm · esm.sh25 Şub 2026