Skip to content
Noroxi

openshift devspaces records

18 published records for vendor openshift devspaces.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
94.4%
Median publish → KEV
No record has entered KEV

All records

18 records
  • Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

    CriticalCVSS 9.3No exploitEPSS 1%

    apostrophecms · sanitize-htmlJun 12, 2026

  • GOSTCTR implementation unable to process more than 255 blocks correctly

    CriticalCVSS 9.3No exploitEPSS 0%

    legion of the bouncy castle inc. · bc-javaApr 15, 2026

  • CVE-2026-9277
    36Monitor

    shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`

    CriticalCVSS 9.2Proof of conceptEPSS 1%

    May 22, 2026

  • CVE-2026-5598
    35Monitor

    Non-constant time comparisons risk private key leakage in FrodoKEM.

    HighCVSS 8.9No exploitEPSS 1%

    legion of the bouncy castle inc. · bc-javaApr 15, 2026

  • Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider

    HighCVSS 8.8No exploitEPSS 1%

    go-acme · legoApr 21, 2026

  • CVE-2026-1761
    34Monitor

    Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response

    HighCVSS 8.6No exploitEPSS 1%

    red hat · red hat enterprise linux 10Feb 2, 2026

  • form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

    HighCVSS 8.7No exploitEPSS 1%

    form-data · form-dataJun 12, 2026

  • CVE-2026-0719
    34Monitor

    Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication

    HighCVSS 8.6No exploitEPSS 1%

    red hat · red hat enterprise linux 10Jan 8, 2026

  • CVE-2026-0603
    33Monitor

    Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection

    HighCVSS 8.3Proof of conceptEPSS 1%

    red hat · red hat jboss enterprise application platform 7.1 eus for rhel 7Jan 23, 2026

  • Micrometer HTTP server instrumentations DoS vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    spring · micrometerJun 9, 2026

  • Micrometer gRPC server instrumentation DoS vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    spring · micrometerJun 9, 2026

  • xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

    HighCVSS 7.5No exploitEPSS 1%

    xmldom · xmldomApr 2, 2026

  • launch-editor vulnerable to command injection via the crafted request on Windows

    HighCVSS 7.5Proof of conceptEPSS 1%

    vitejs · launch-editorJun 1, 2026

  • CVE-2026-0775
    28Monitor

    npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability

    HighCVSS 7.0No exploitEPSS 0%

    npm · cliJan 23, 2026

  • CVE-2026-5588
    25Monitor

    PKIX draft CompositeVerifier accepts empty signature sequence as valid.

    MediumCVSS 6.3No exploitEPSS 1%

    legion of the bouncy castle inc. · bc-javaApr 15, 2026

  • CVE-2026-0636
    22Monitor

    LDAP Injection Vulnerability in LDAPStoreHelper.java

    MediumCVSS 5.5No exploitEPSS 1%

    legion of the bouncy castle inc. · bc-javaApr 15, 2026

  • opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation

    MediumCVSS 5.3No exploitEPSS 1%

    open-telemetry · opentelemetry-javaMay 28, 2026

  • ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena

    LowCVSS 2.9No exploitEPSS 1%

    ajv.js · ajvFeb 11, 2026