linuxfoundation kayıtları
linuxfoundation üreticisine ait 560 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,2
- Silahlaştırılmış
- 4 · %0,7
- Pre-auth RCE
- 27
- Düzeltme kaydı olan
- %56,6
- Yayından KEV’e ortanca
- 16 gün
Tekrar eden sınıflar
- CWE-787 Out-of-bounds Write55
- CWE-125 Out-of-bounds Read31
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')27
- CWE-476 NULL Pointer Dereference25
- CWE-863 Incorrect Authorization22
- CWE-400 Uncontrolled Resource Consumption22
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
560 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2026-45321Silahlaştırılmış | Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keystanstack · tanstack\/arktype-adapter · CWE-506 | Kritik9,6 | KEV | %1,1 | 11 May 2026 |
64Bu hafta | CVE-2019-5736Silahlaştırılmış | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | Yüksek8,6 | — | %98,5 | 11 Şub 2019 |
49Planlayın | CVE-2023-27584Kavram kanıtı | Dragonfly2 vulnerable to hard coded cyptographic keylinuxfoundation · dragonfly · CWE-321 | Kritik9,8 | — | %33,6 | 19 Eyl 2024 |
48Planlayın | CVE-2021-23450İstismar yok | All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.linuxfoundation · dojo · CWE-1321 | Kritik9,8 | — | %30,4 | 17 Ara 2021 |
41Planlayın | CVE-2010-5325İstismar yok | Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denredhat · enterprise linux desktop · CWE-119 | Kritik9,8 | — | %5,5 | 15 Nis 2016 |
40Planlayın | CVE-2019-1010245İstismar yok | The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation.linuxfoundation · open network operating system · CWE-20 | Kritik9,8 | — | %3,6 | 19 Tem 2019 |
40Planlayın | CVE-2021-43832İstismar yok | Improper Access Control in spinnakerlinuxfoundation · spinnaker · CWE-306 | Kritik9,8 | — | %2,6 | 4 Oca 2022 |
40Planlayın | CVE-2020-26892İstismar yok | The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.linuxfoundation · nats-server · CWE-798 | Kritik9,8 | — | %2,1 | 6 Kas 2020 |
40Planlayın | CVE-2023-35926İstismar yok | Insecure sandbox in Backstage Scaffolder pluginlinuxfoundation · backstage · CWE-94 | Kritik9,9 | — | %1,9 | 22 Haz 2023 |
40Planlayın | CVE-2020-27847İstismar yok | A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.linuxfoundation · dex · CWE-228 | Kritik9,8 | — | %1,7 | 28 May 2021 |
40Planlayın | CVE-2019-1010234İstismar yok | The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation.linuxfoundation · open network operating system · CWE-20 | Kritik9,8 | — | %1,7 | 22 Tem 2019 |
40Planlayın | CVE-2022-35942İstismar yok | loopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filterlinuxfoundation · loopback-connector-postgresql · CWE-89 | Kritik10,0 | — | %0,6 | 12 Ağu 2022 |
39İzleyin | CVE-2024-21626Silahlaştırılmış | runc container breakout through process.cwd trickery and leaked fdslinuxfoundation · runc · CWE-403 | Yüksek8,6 | — | %18,1 | 31 Oca 2024 |
39İzleyin | CVE-2024-48063İstismar yok | In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE.linuxfoundation · pytorch · CWE-502 | Kritik9,8 | — | %1,6 | 29 Eki 2024 |
39İzleyin | CVE-2021-39228İstismar yok | Memory Safety Issue when using patch or merge on state and assign the result back to statelinuxfoundation · tremor · CWE-416 | Kritik9,8 | — | %1,3 | 17 Eyl 2021 |
39İzleyin | CVE-2022-45907İstismar yok | In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.linuxfoundation · pytorch · CWE-94 | Kritik9,8 | — | %1,3 | 25 Kas 2022 |
39İzleyin | CVE-2024-25626İstismar yok | Yocto Project Security Advisory - BitBake/Toasterlinuxfoundation · yocto · CWE-78 | Kritik9,8 | — | %1,2 | 19 Şub 2024 |
39İzleyin | CVE-2021-45701İstismar yok | An issue was discovered in the tremor-script crate before 0.11.6 for Rust.linuxfoundation · tremor-script · CWE-416 | Kritik9,8 | — | %1,2 | 26 Ara 2021 |
39İzleyin | CVE-2022-28357İstismar yok | NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management accoulinuxfoundation · nats-server · CWE-22 | Kritik9,8 | — | %1,2 | 18 Eyl 2023 |
39İzleyin | CVE-2020-6174İstismar yok | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.linuxfoundation · the update framework · CWE-347 | Kritik9,8 | — | %1,0 | 5 Şub 2020 |
39İzleyin | CVE-2021-32163İstismar yok | Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.linuxfoundation · modular open smart network · CWE-863 | Kritik9,8 | — | %0,9 | 17 Şub 2023 |
39İzleyin | CVE-2024-24421İstismar yok | A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allowslinuxfoundation · magma · CWE-94 | Kritik9,8 | — | %0,9 | 21 Oca 2025 |
39İzleyin | CVE-2026-29186İstismar yok | @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Executionlinuxfoundation · backstage plugin-techdocs-node · CWE-74 | Kritik9,8 | — | %0,9 | 7 Mar 2026 |
39İzleyin | CVE-2026-35171İstismar yok | Arbitrary Code Execution via Malicious Logging Configuration in Kedrolinuxfoundation · kedro · CWE-94 | Kritik9,8 | — | %0,9 | 6 Nis 2026 |
39İzleyin | CVE-2026-37531İstismar yok | AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367linuxfoundation · automotive grade linux · CWE-22 | Kritik9,8 | — | %0,9 | 1 May 2026 |
- CVE-2026-4532168Bu hafta
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
KritikCVSS 9,6KEVSilahlaştırılmışEPSS %1tanstack · tanstack\/arktype-adapter11 May 2026
- CVE-2019-573664Bu hafta
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
YüksekCVSS 8,6SilahlaştırılmışEPSS %98docker · docker11 Şub 2019
- CVE-2023-2758449Planlayın
Dragonfly2 vulnerable to hard coded cyptographic key
KritikCVSS 9,8Kavram kanıtıEPSS %34linuxfoundation · dragonfly19 Eyl 2024
- CVE-2021-2345048Planlayın
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
KritikCVSS 9,8İstismar yokEPSS %30linuxfoundation · dojo17 Ara 2021
- CVE-2010-532541Planlayın
Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a den
KritikCVSS 9,8İstismar yokEPSS %5redhat · enterprise linux desktop15 Nis 2016
- CVE-2019-101024540Planlayın
The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation.
KritikCVSS 9,8İstismar yokEPSS %4linuxfoundation · open network operating system19 Tem 2019
- CVE-2021-4383240Planlayın
Improper Access Control in spinnaker
KritikCVSS 9,8İstismar yokEPSS %3linuxfoundation · spinnaker4 Oca 2022
- CVE-2020-2689240Planlayın
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
KritikCVSS 9,8İstismar yokEPSS %2linuxfoundation · nats-server6 Kas 2020
- CVE-2023-3592640Planlayın
Insecure sandbox in Backstage Scaffolder plugin
KritikCVSS 9,9İstismar yokEPSS %2linuxfoundation · backstage22 Haz 2023
- CVE-2020-2784740Planlayın
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.
KritikCVSS 9,8İstismar yokEPSS %2linuxfoundation · dex28 May 2021
- CVE-2019-101023440Planlayın
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation.
KritikCVSS 9,8İstismar yokEPSS %2linuxfoundation · open network operating system22 Tem 2019
- CVE-2022-3594240Planlayın
loopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filter
KritikCVSS 10,0İstismar yokEPSS %1linuxfoundation · loopback-connector-postgresql12 Ağu 2022
- CVE-2024-2162639İzleyin
runc container breakout through process.cwd trickery and leaked fds
YüksekCVSS 8,6SilahlaştırılmışEPSS %18linuxfoundation · runc31 Oca 2024
- CVE-2024-4806339İzleyin
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE.
KritikCVSS 9,8İstismar yokEPSS %2linuxfoundation · pytorch29 Eki 2024
- CVE-2021-3922839İzleyin
Memory Safety Issue when using patch or merge on state and assign the result back to state
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · tremor17 Eyl 2021
- CVE-2022-4590739İzleyin
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · pytorch25 Kas 2022
- CVE-2024-2562639İzleyin
Yocto Project Security Advisory - BitBake/Toaster
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · yocto19 Şub 2024
- CVE-2021-4570139İzleyin
An issue was discovered in the tremor-script crate before 0.11.6 for Rust.
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · tremor-script26 Ara 2021
- CVE-2022-2835739İzleyin
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management accou
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · nats-server18 Eyl 2023
- CVE-2020-617439İzleyin
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · the update framework5 Şub 2020
- CVE-2021-3216339İzleyin
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · modular open smart network17 Şub 2023
- CVE-2024-2442139İzleyin
A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · magma21 Oca 2025
- CVE-2026-2918639İzleyin
@backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · backstage plugin-techdocs-node7 Mar 2026
- CVE-2026-3517139İzleyin
Arbitrary Code Execution via Malicious Logging Configuration in Kedro
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · kedro6 Nis 2026
- CVE-2026-3753139İzleyin
AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367
KritikCVSS 9,8İstismar yokEPSS %1linuxfoundation · automotive grade linux1 May 2026