Записи trychroma
4 опубликованных записей вендора trychroma.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-863 Incorrect Authorization1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2026-45833Proof of concept | A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary ctrychroma · chromadb · CWE-94 | Критическая9,4 | — | 0,6 % | 12 июн. 2026 г. |
35Наблюдать | CVE-2026-45832Эксплойта нет | All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attrychroma · chromadb · CWE-639 | Высокая8,8 | — | 0,5 % | 12 июн. 2026 г. |
35Наблюдать | CVE-2026-45830Эксплойта нет | A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily rtrychroma · chromadb · CWE-639 | Высокая8,8 | — | 0,5 % | 12 июн. 2026 г. |
35Наблюдать | CVE-2026-45831Эксплойта нет | The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a usetrychroma · chromadb · CWE-863 | Высокая8,8 | — | 0,4 % | 12 июн. 2026 г. |
- CVE-2026-4583337Наблюдать
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary c
КритическаяCVSS 9,4Proof of conceptEPSS 1 %trychroma · chromadb12 июн. 2026 г.
- CVE-2026-4583235Наблюдать
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing at
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %trychroma · chromadb12 июн. 2026 г.
- CVE-2026-4583035Наблюдать
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily r
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %trychroma · chromadb12 июн. 2026 г.
- CVE-2026-4583135Наблюдать
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a use
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %trychroma · chromadb12 июн. 2026 г.