acm records
13 published records for vendor acm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 76.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-190 Integer Overflow or Wraparound1
- CWE-29 Path Traversal: '\..\filename'1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-427 Uncontrolled Search Path Element1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-44990No exploit | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`apostrophecms · sanitize-html · CWE-79 | Critical9.3 | — | 0.7% | Jun 12, 2026 |
34Monitor | CVE-2026-46384No exploit | iskorotkov/avro: Integer Overflow in Avro Decoderiskorotkov · avro · CWE-190 | High8.7 | — | 0.9% | May 29, 2026 |
34Monitor | CVE-2026-46385No exploit | iskorotkov/avro: CPU Exhaustion in Avro Decoderiskorotkov · avro · CWE-400 | High8.7 | — | 0.9% | May 29, 2026 |
34Monitor | CVE-2026-35469No exploit | SpdyStream: DOS on CRImoby · spdystream · CWE-770 | High8.7 | — | 0.8% | Apr 16, 2026 |
34Monitor | CVE-2026-12143No exploit | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | High8.7 | — | 0.7% | Jun 12, 2026 |
31Monitor | CVE-2026-44724No exploit | systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile namesebhildebrandt · systeminformation · CWE-78 | High7.8 | — | 1.2% | May 27, 2026 |
31Monitor | CVE-2026-11332No exploit | Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code executionred hat · red hat ansible automation platform 2.5 for rhel 8 · CWE-88 | High7.8 | — | 0.2% | Jun 5, 2026 |
28Monitor | CVE-2026-0775No exploit | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm · cli · CWE-732 | High7.0 | — | 0.3% | Jan 23, 2026 |
28Monitor | CVE-2026-41567Proof of concept | Docker: `PUT /containers/{id}/archive` executes container binary on the hostmoby · moby/v2/daemon · CWE-427 | High7.2 | — | 0.2% | Jun 4, 2026 |
28Monitor | CVE-2026-3006No exploit | Race Condition Vulnerabilitywinfsp · winfsp · CWE-362 | High7.0 | — | 0.1% | Apr 26, 2026 |
26Monitor | CVE-2026-27145Proof of concept | Inefficient candidate hostname parsing in crypto/x509go standard library · crypto/x509 · CWE-606 | Medium6.5 | — | 0.6% | Jun 2, 2026 |
22Monitor | CVE-2026-10732No exploit | All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archivCWE-29 | Medium5.6 | — | 0.5% | Jun 5, 2026 |
11Monitor | CVE-2025-69873No exploit | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enaajv.js · ajv · CWE-1333 | Low2.9 | — | 0.5% | Feb 11, 2026 |
- CVE-2026-4499037Monitor
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
CriticalCVSS 9.3No exploitEPSS 1%apostrophecms · sanitize-htmlJun 12, 2026
- CVE-2026-4638434Monitor
iskorotkov/avro: Integer Overflow in Avro Decoder
HighCVSS 8.7No exploitEPSS 1%iskorotkov · avroMay 29, 2026
- CVE-2026-4638534Monitor
iskorotkov/avro: CPU Exhaustion in Avro Decoder
HighCVSS 8.7No exploitEPSS 1%iskorotkov · avroMay 29, 2026
- CVE-2026-3546934Monitor
SpdyStream: DOS on CRI
HighCVSS 8.7No exploitEPSS 1%moby · spdystreamApr 16, 2026
- CVE-2026-1214334Monitor
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
HighCVSS 8.7No exploitEPSS 1%form-data · form-dataJun 12, 2026
- CVE-2026-4472431Monitor
systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name
HighCVSS 7.8No exploitEPSS 1%sebhildebrandt · systeminformationMay 27, 2026
- CVE-2026-1133231Monitor
Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
HighCVSS 7.8No exploitEPSS 0%red hat · red hat ansible automation platform 2.5 for rhel 8Jun 5, 2026
- CVE-2026-077528Monitor
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
HighCVSS 7.0No exploitEPSS 0%npm · cliJan 23, 2026
- CVE-2026-4156728Monitor
Docker: `PUT /containers/{id}/archive` executes container binary on the host
HighCVSS 7.2Proof of conceptEPSS 0%moby · moby/v2/daemonJun 4, 2026
- CVE-2026-300628Monitor
Race Condition Vulnerability
HighCVSS 7.0No exploitEPSS 0%winfsp · winfspApr 26, 2026
- CVE-2026-2714526Monitor
Inefficient candidate hostname parsing in crypto/x509
MediumCVSS 6.5Proof of conceptEPSS 1%go standard library · crypto/x509Jun 2, 2026
- CVE-2026-1073222Monitor
All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archiv
MediumCVSS 5.6No exploitEPSS 1%Jun 5, 2026
- CVE-2025-6987311Monitor
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena
LowCVSS 2.9No exploitEPSS 1%ajv.js · ajvFeb 11, 2026