serverless records
3 published records for vendor serverless.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2025-69256Proof of concept | serverless MCP Server vulnerable to command injection in list-projects toolserverless · serverless · CWE-77 | High7.5 | — | 2.4% | Dec 30, 2025 |
28Monitor | CVE-2026-0775No exploit | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm · cli · CWE-732 | High7.0 | — | 0.3% | Jan 23, 2026 |
21Monitor | CVE-2026-45292No exploit | opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagationopen-telemetry · opentelemetry-java · CWE-770 | Medium5.3 | — | 0.8% | May 28, 2026 |
- CVE-2025-6925631Monitor
serverless MCP Server vulnerable to command injection in list-projects tool
HighCVSS 7.5Proof of conceptEPSS 2%serverless · serverlessDec 30, 2025
- CVE-2026-077528Monitor
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
HighCVSS 7.0No exploitEPSS 0%npm · cliJan 23, 2026
- CVE-2026-4529221Monitor
opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
MediumCVSS 5.3No exploitEPSS 1%open-telemetry · opentelemetry-javaMay 28, 2026