rhdh kayıtları
rhdh üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %92,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-91 XML Injection (aka Blind XPath Injection)4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-606 Unchecked Input for Loop Condition1
- CWE-674 Uncontrolled Recursion1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2026-9277Kavram kanıtı | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Kritik9,2 | — | %1,0 | 22 May 2026 |
34İzleyin | CVE-2026-41673İstismar yok | xmldom: Denial of service via uncontrolled recursion in XML serializationxmldom · xmldom · CWE-674 | Yüksek8,7 | — | %0,9 | 7 May 2026 |
34İzleyin | CVE-2026-12143İstismar yok | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | Yüksek8,7 | — | %0,7 | 12 Haz 2026 |
34İzleyin | CVE-2026-41672İstismar yok | xmldom: XML node injection through unvalidated comment serializationxmldom · xmldom · CWE-91 | Yüksek8,7 | — | %0,7 | 7 May 2026 |
34İzleyin | CVE-2026-41674İstismar yok | xmldom: XML injection through unvalidated DocumentType serializationxmldom · xmldom · CWE-91 | Yüksek8,7 | — | %0,7 | 7 May 2026 |
34İzleyin | CVE-2026-41675İstismar yok | xmldom: XML node injection through unvalidated processing instruction serializationxmldom · xmldom · CWE-91 | Yüksek8,7 | — | %0,6 | 7 May 2026 |
32İzleyin | CVE-2026-1615İstismar yok | Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path exCWE-94 | Yüksek8,2 | — | %1,1 | 9 Şub 2026 |
31İzleyin | CVE-2026-44724İstismar yok | systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile namesebhildebrandt · systeminformation · CWE-78 | Yüksek7,8 | — | %1,2 | 27 May 2026 |
30İzleyin | CVE-2026-34601İstismar yok | xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertionxmldom · xmldom · CWE-91 | Yüksek7,5 | — | %0,5 | 2 Nis 2026 |
30İzleyin | CVE-2024-52011Kavram kanıtı | launch-editor vulnerable to command injection via the crafted request on Windowsvitejs · launch-editor · CWE-77 | Yüksek7,5 | — | %0,5 | 1 Haz 2026 |
28İzleyin | CVE-2026-24046İstismar yok | Backstage has a Possible Symlink Path Traversal in Scaffolder Actionsbackstage · backstage · CWE-22 | Yüksek7,1 | — | %0,5 | 21 Oca 2026 |
28İzleyin | CVE-2026-0775İstismar yok | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm · cli · CWE-732 | Yüksek7,0 | — | %0,3 | 23 Oca 2026 |
26İzleyin | CVE-2026-27145Kavram kanıtı | Inefficient candidate hostname parsing in crypto/x509go standard library · crypto/x509 · CWE-606 | Orta6,5 | — | %0,6 | 2 Haz 2026 |
11İzleyin | CVE-2025-69873İstismar yok | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enaajv.js · ajv · CWE-1333 | Düşük2,9 | — | %0,5 | 11 Şub 2026 |
- CVE-2026-927736İzleyin
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
KritikCVSS 9,2Kavram kanıtıEPSS %122 May 2026
- CVE-2026-4167334İzleyin
xmldom: Denial of service via uncontrolled recursion in XML serialization
YüksekCVSS 8,7İstismar yokEPSS %1xmldom · xmldom7 May 2026
- CVE-2026-1214334İzleyin
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
YüksekCVSS 8,7İstismar yokEPSS %1form-data · form-data12 Haz 2026
- CVE-2026-4167234İzleyin
xmldom: XML node injection through unvalidated comment serialization
YüksekCVSS 8,7İstismar yokEPSS %1xmldom · xmldom7 May 2026
- CVE-2026-4167434İzleyin
xmldom: XML injection through unvalidated DocumentType serialization
YüksekCVSS 8,7İstismar yokEPSS %1xmldom · xmldom7 May 2026
- CVE-2026-4167534İzleyin
xmldom: XML node injection through unvalidated processing instruction serialization
YüksekCVSS 8,7İstismar yokEPSS %1xmldom · xmldom7 May 2026
- CVE-2026-161532İzleyin
Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path ex
YüksekCVSS 8,2İstismar yokEPSS %19 Şub 2026
- CVE-2026-4472431İzleyin
systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name
YüksekCVSS 7,8İstismar yokEPSS %1sebhildebrandt · systeminformation27 May 2026
- CVE-2026-3460130İzleyin
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
YüksekCVSS 7,5İstismar yokEPSS %1xmldom · xmldom2 Nis 2026
- CVE-2024-5201130İzleyin
launch-editor vulnerable to command injection via the crafted request on Windows
YüksekCVSS 7,5Kavram kanıtıEPSS %1vitejs · launch-editor1 Haz 2026
- CVE-2026-2404628İzleyin
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
YüksekCVSS 7,1İstismar yokEPSS %1backstage · backstage21 Oca 2026
- CVE-2026-077528İzleyin
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
YüksekCVSS 7,0İstismar yokEPSS %0npm · cli23 Oca 2026
- CVE-2026-2714526İzleyin
Inefficient candidate hostname parsing in crypto/x509
OrtaCVSS 6,5Kavram kanıtıEPSS %1go standard library · crypto/x5092 Haz 2026
- CVE-2025-6987311İzleyin
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena
DüşükCVSS 2,9İstismar yokEPSS %1ajv.js · ajv11 Şub 2026