Skip to content
Noroxi

linuxfoundation records

560 published records for vendor linuxfoundation.

Researcher profile

Entered KEV
1 · 0.2%
Weaponized
4 · 0.7%
Pre-auth RCE
27
With a fix record
56.6%
Median publish → KEV
16 days

All records

560 records
  • CVE-2026-45321
    68This week

    Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

    CriticalCVSS 9.6KEVWeaponizedEPSS 1%

    tanstack · tanstack\/arktype-adapterMay 11, 2026

  • CVE-2019-5736
    64This week

    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen

    HighCVSS 8.6WeaponizedEPSS 98%

    docker · dockerFeb 11, 2019

  • Dragonfly2 vulnerable to hard coded cyptographic key

    CriticalCVSS 9.8Proof of conceptEPSS 34%

    linuxfoundation · dragonflySep 19, 2024

  • All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

    CriticalCVSS 9.8No exploitEPSS 30%

    linuxfoundation · dojoDec 17, 2021

  • Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a den

    CriticalCVSS 9.8No exploitEPSS 5%

    redhat · enterprise linux desktopApr 15, 2016

  • runc container breakout through process.cwd trickery and leaked fds

    HighCVSS 8.6WeaponizedEPSS 19%

    linuxfoundation · runcJan 31, 2024

  • The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation.

    CriticalCVSS 9.8No exploitEPSS 4%

    linuxfoundation · open network operating systemJul 19, 2019

  • Improper Access Control in spinnaker

    CriticalCVSS 9.8No exploitEPSS 3%

    linuxfoundation · spinnakerJan 4, 2022

  • The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.

    CriticalCVSS 9.8No exploitEPSS 2%

    linuxfoundation · nats-serverNov 6, 2020

  • Insecure sandbox in Backstage Scaffolder plugin

    CriticalCVSS 9.9No exploitEPSS 2%

    linuxfoundation · backstageJun 22, 2023

  • A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.

    CriticalCVSS 9.8No exploitEPSS 2%

    linuxfoundation · dexMay 28, 2021

  • The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation.

    CriticalCVSS 9.8No exploitEPSS 2%

    linuxfoundation · open network operating systemJul 22, 2019

  • loopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filter

    CriticalCVSS 10.0No exploitEPSS 1%

    linuxfoundation · loopback-connector-postgresqlAug 12, 2022

  • In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE.

    CriticalCVSS 9.8No exploitEPSS 2%

    linuxfoundation · pytorchOct 29, 2024

  • Memory Safety Issue when using patch or merge on state and assign the result back to state

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · tremorSep 17, 2021

  • In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · pytorchNov 25, 2022

  • Yocto Project Security Advisory - BitBake/Toaster

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · yoctoFeb 19, 2024

  • An issue was discovered in the tremor-script crate before 0.11.6 for Rust.

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · tremor-scriptDec 26, 2021

  • NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management accou

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · nats-serverSep 18, 2023

  • CVE-2020-6174
    39Monitor

    TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · the update frameworkFeb 5, 2020

  • Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · modular open smart networkFeb 17, 2023

  • A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · magmaJan 21, 2025

  • @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · backstage plugin-techdocs-nodeMar 7, 2026

  • Arbitrary Code Execution via Malicious Logging Configuration in Kedro

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · kedroApr 6, 2026

  • AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367

    CriticalCVSS 9.8No exploitEPSS 1%

    linuxfoundation · automotive grade linuxMay 1, 2026