Skip to content
Noroxi

discovery records

7 published records for vendor discovery.

All records

7 records
  • CVE-2026-9277
    36Monitor

    shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`

    CriticalCVSS 9.2Proof of conceptEPSS 1%

    May 22, 2026

  • acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions

    HighCVSS 8.4No exploitEPSS 0%

    acl project · aclJun 29, 2026

  • attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr

    HighCVSS 8.4No exploitEPSS 0%

    attr project · attrJun 29, 2026

  • Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution

    HighCVSS 7.8No exploitEPSS 0%

    red hat · red hat ansible automation platform 2.5 for rhel 8Jun 5, 2026

  • Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly

    HighCVSS 7.5No exploitEPSS 1%

    red hat · red hat enterprise linux 10May 4, 2026

  • CVE-2026-4111
    30Monitor

    Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive

    HighCVSS 7.5No exploitEPSS 1%

    red hat · red hat enterprise linux 10Mar 13, 2026

  • launch-editor vulnerable to command injection via the crafted request on Windows

    HighCVSS 7.5Proof of conceptEPSS 1%

    vitejs · launch-editorJun 1, 2026