discovery records
7 published records for vendor discovery.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-130 Improper Handling of Length Parameter Inconsistency1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2026-9277Proof of concept | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Critical9.2 | — | 1.0% | May 22, 2026 |
33Monitor | CVE-2026-54369No exploit | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functionsacl project · acl · CWE-59 | High8.4 | — | 0.2% | Jun 29, 2026 |
33Monitor | CVE-2026-54371No exploit | attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattrattr project · attr · CWE-59 | High8.4 | — | 0.2% | Jun 29, 2026 |
31Monitor | CVE-2026-11332No exploit | Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code executionred hat · red hat ansible automation platform 2.5 for rhel 8 · CWE-88 | High7.8 | — | 0.2% | Jun 5, 2026 |
30Monitor | CVE-2026-33846No exploit | Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassemblyred hat · red hat enterprise linux 10 · CWE-130 | High7.5 | — | 1.1% | May 4, 2026 |
30Monitor | CVE-2026-4111No exploit | Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchivered hat · red hat enterprise linux 10 · CWE-835 | High7.5 | — | 0.9% | Mar 13, 2026 |
30Monitor | CVE-2024-52011Proof of concept | launch-editor vulnerable to command injection via the crafted request on Windowsvitejs · launch-editor · CWE-77 | High7.5 | — | 0.5% | Jun 1, 2026 |
- CVE-2026-927736Monitor
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
CriticalCVSS 9.2Proof of conceptEPSS 1%May 22, 2026
- CVE-2026-5436933Monitor
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
HighCVSS 8.4No exploitEPSS 0%acl project · aclJun 29, 2026
- CVE-2026-5437133Monitor
attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
HighCVSS 8.4No exploitEPSS 0%attr project · attrJun 29, 2026
- CVE-2026-1133231Monitor
Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
HighCVSS 7.8No exploitEPSS 0%red hat · red hat ansible automation platform 2.5 for rhel 8Jun 5, 2026
- CVE-2026-3384630Monitor
Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
HighCVSS 7.5No exploitEPSS 1%red hat · red hat enterprise linux 10May 4, 2026
- CVE-2026-411130Monitor
Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive
HighCVSS 7.5No exploitEPSS 1%red hat · red hat enterprise linux 10Mar 13, 2026
- CVE-2024-5201130Monitor
launch-editor vulnerable to command injection via the crafted request on Windows
HighCVSS 7.5Proof of conceptEPSS 1%vitejs · launch-editorJun 1, 2026