Mark Esler (https://github.com/eslerm)
6 credited records · 6 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2026-47364No exploit | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no userdatadog · android app · CWE-200 | Medium6.5 | — | 0.4% | Aug 7, 2026 |
25Monitor | CVE-2026-47363No exploit | In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied datadog · android app · CWE-926 | Medium6.3 | — | 0.2% | Aug 7, 2026 |
18Monitor | CVE-2026-47362No exploit | In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: Ldatadog · android app · CWE-922 | Medium4.6 | — | 0.2% | Aug 7, 2026 |
25Monitor | CVE-2026-47361No exploit | In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEdatadog · android app · CWE-926 | Medium6.4 | — | 0.3% | Aug 7, 2026 |
22Monitor | CVE-2026-44965No exploit | In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, Monitordatadog · android app · CWE-926 | Medium5.5 | — | 0.2% | Aug 7, 2026 |
26Monitor | CVE-2026-44964No exploit | In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guarddatadog · android app · CWE-441 | Medium6.5 | — | 0.3% | Aug 7, 2026 |
- CVE-2026-4736426Monitor
In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user
MediumCVSS 6.5No exploitEPSS 0%datadog · android appAug 7, 2026
- CVE-2026-4736325Monitor
In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied
MediumCVSS 6.3No exploitEPSS 0%datadog · android appAug 7, 2026
- CVE-2026-4736218Monitor
In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: L
MediumCVSS 4.6No exploitEPSS 0%datadog · android appAug 7, 2026
- CVE-2026-4736125Monitor
In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SE
MediumCVSS 6.4No exploitEPSS 0%datadog · android appAug 7, 2026
- CVE-2026-4496522Monitor
In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, Monitor
MediumCVSS 5.5No exploitEPSS 0%datadog · android appAug 7, 2026
- CVE-2026-4496426Monitor
In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard
MediumCVSS 6.5No exploitEPSS 0%datadog · android appAug 7, 2026