Записи hex
9 опубликованных записей вендора hex.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption2
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-613 Insufficient Session Expiration1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2026-21622Эксплойта нет | Password Reset Tokens Do Not Expirehex · hexpm · CWE-613 | Критическая9,5 | — | 0,4 % | 5 мар. 2026 г. |
35Наблюдать | CVE-2019-1000013Эксплойта нет | Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can reshex · hex core · CWE-345 | Высокая8,8 | — | 0,9 % | 4 февр. 2019 г. |
35Наблюдать | CVE-2019-1000012Эксплойта нет | Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result ihex · hex · CWE-345 | Высокая8,8 | — | 0,9 % | 4 февр. 2019 г. |
35Наблюдать | CVE-2026-32148Эксплойта нет | Lockfile checksums not verified in Hex allows dependency integrity bypasshex · hex · CWE-354 | Высокая8,9 | — | 0,3 % | 30 апр. 2026 г. |
34Наблюдать | CVE-2026-21618Эксплойта нет | Cross-site scripting (XSS) in OAuth Device Authorization screenhex · hexpm · CWE-79 | Высокая8,5 | — | 0,3 % | 19 янв. 2026 г. |
28Наблюдать | CVE-2026-23940Эксплойта нет | Denial of Service via Oversized Package Uploadhex · hexpm · CWE-400 | Высокая7,1 | — | 0,4 % | 13 мар. 2026 г. |
28Наблюдать | CVE-2026-21621Эксплойта нет | Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Accesshex · hexpm · CWE-863 | Высокая7,0 | — | 0,3 % | 5 мар. 2026 г. |
27Наблюдать | CVE-2026-23939Эксплойта нет | Path Traversal in Local File Store Backendhex · hexpm · CWE-22 | Средняя6,9 | — | 0,4 % | 26 февр. 2026 г. |
8Наблюдать | CVE-2026-21619Эксплойта нет | Unsafe Deserialization of Erlang Terms in hex_corehex · hex · CWE-400 | Низкая2,0 | — | 0,6 % | 27 февр. 2026 г. |
- CVE-2026-2162238Наблюдать
Password Reset Tokens Do Not Expire
КритическаяCVSS 9,5Эксплойта нетEPSS 0 %hex · hexpm5 мар. 2026 г.
- CVE-2019-100001335Наблюдать
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can res
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hex · hex core4 февр. 2019 г.
- CVE-2019-100001235Наблюдать
Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result i
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hex · hex4 февр. 2019 г.
- CVE-2026-3214835Наблюдать
Lockfile checksums not verified in Hex allows dependency integrity bypass
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %hex · hex30 апр. 2026 г.
- CVE-2026-2161834Наблюдать
Cross-site scripting (XSS) in OAuth Device Authorization screen
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %hex · hexpm19 янв. 2026 г.
- CVE-2026-2394028Наблюдать
Denial of Service via Oversized Package Upload
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %hex · hexpm13 мар. 2026 г.
- CVE-2026-2162128Наблюдать
Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %hex · hexpm5 мар. 2026 г.
- CVE-2026-2393927Наблюдать
Path Traversal in Local File Store Backend
СредняяCVSS 6,9Эксплойта нетEPSS 0 %hex · hexpm26 февр. 2026 г.
- CVE-2026-216198Наблюдать
Unsafe Deserialization of Erlang Terms in hex_core
НизкаяCVSS 2,0Эксплойта нетEPSS 1 %hex · hex27 февр. 2026 г.