Skip to content
Noroxi

acm records

13 published records for vendor acm.

All records

13 records
  • Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

    CriticalCVSS 9.3No exploitEPSS 1%

    apostrophecms · sanitize-htmlJun 12, 2026

  • iskorotkov/avro: Integer Overflow in Avro Decoder

    HighCVSS 8.7No exploitEPSS 1%

    iskorotkov · avroMay 29, 2026

  • iskorotkov/avro: CPU Exhaustion in Avro Decoder

    HighCVSS 8.7No exploitEPSS 1%

    iskorotkov · avroMay 29, 2026

  • SpdyStream: DOS on CRI

    HighCVSS 8.7No exploitEPSS 1%

    moby · spdystreamApr 16, 2026

  • form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

    HighCVSS 8.7No exploitEPSS 1%

    form-data · form-dataJun 12, 2026

  • systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name

    HighCVSS 7.8No exploitEPSS 1%

    sebhildebrandt · systeminformationMay 27, 2026

  • Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution

    HighCVSS 7.8No exploitEPSS 0%

    red hat · red hat ansible automation platform 2.5 for rhel 8Jun 5, 2026

  • CVE-2026-0775
    28Monitor

    npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability

    HighCVSS 7.0No exploitEPSS 0%

    npm · cliJan 23, 2026

  • Docker: `PUT /containers/{id}/archive` executes container binary on the host

    HighCVSS 7.2Proof of conceptEPSS 0%

    moby · moby/v2/daemonJun 4, 2026

  • CVE-2026-3006
    28Monitor

    Race Condition Vulnerability

    HighCVSS 7.0No exploitEPSS 0%

    winfsp · winfspApr 26, 2026

  • Inefficient candidate hostname parsing in crypto/x509

    MediumCVSS 6.5Proof of conceptEPSS 1%

    go standard library · crypto/x509Jun 2, 2026

  • All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archiv

    MediumCVSS 5.6No exploitEPSS 1%

    Jun 5, 2026

  • ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena

    LowCVSS 2.9No exploitEPSS 1%

    ajv.js · ajvFeb 11, 2026