linuxfoundation records
560 published records for vendor linuxfoundation.
Researcher profile
- Entered KEV
- 1 · 0.2%
- Weaponized
- 4 · 0.7%
- Pre-auth RCE
- 27
- With a fix record
- 56.6%
- Median publish → KEV
- 16 days
Recurring classes
- CWE-787 Out-of-bounds Write55
- CWE-125 Out-of-bounds Read31
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')27
- CWE-476 NULL Pointer Dereference25
- CWE-863 Incorrect Authorization22
- CWE-400 Uncontrolled Resource Consumption22
The weakness classes this vendor ships most often: where to look.
CWEAll records
560 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2026-45321Weaponized | Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keystanstack · tanstack\/arktype-adapter · CWE-506 | Critical9.6 | KEV | 1.1% | May 11, 2026 |
64This week | CVE-2019-5736Weaponized | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | High8.6 | — | 98.5% | Feb 11, 2019 |
49Plan | CVE-2023-27584Proof of concept | Dragonfly2 vulnerable to hard coded cyptographic keylinuxfoundation · dragonfly · CWE-321 | Critical9.8 | — | 33.9% | Sep 19, 2024 |
48Plan | CVE-2021-23450No exploit | All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.linuxfoundation · dojo · CWE-1321 | Critical9.8 | — | 30.4% | Dec 17, 2021 |
41Plan | CVE-2010-5325No exploit | Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denredhat · enterprise linux desktop · CWE-119 | Critical9.8 | — | 5.5% | Apr 15, 2016 |
40Plan | CVE-2024-21626Weaponized | runc container breakout through process.cwd trickery and leaked fdslinuxfoundation · runc · CWE-403 | High8.6 | — | 18.9% | Jan 31, 2024 |
40Plan | CVE-2019-1010245No exploit | The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation.linuxfoundation · open network operating system · CWE-20 | Critical9.8 | — | 3.6% | Jul 19, 2019 |
40Plan | CVE-2021-43832No exploit | Improper Access Control in spinnakerlinuxfoundation · spinnaker · CWE-306 | Critical9.8 | — | 2.6% | Jan 4, 2022 |
40Plan | CVE-2020-26892No exploit | The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.linuxfoundation · nats-server · CWE-798 | Critical9.8 | — | 2.1% | Nov 6, 2020 |
40Plan | CVE-2023-35926No exploit | Insecure sandbox in Backstage Scaffolder pluginlinuxfoundation · backstage · CWE-94 | Critical9.9 | — | 1.9% | Jun 22, 2023 |
40Plan | CVE-2020-27847No exploit | A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.linuxfoundation · dex · CWE-228 | Critical9.8 | — | 1.7% | May 28, 2021 |
40Plan | CVE-2019-1010234No exploit | The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation.linuxfoundation · open network operating system · CWE-20 | Critical9.8 | — | 1.7% | Jul 22, 2019 |
40Plan | CVE-2022-35942No exploit | loopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filterlinuxfoundation · loopback-connector-postgresql · CWE-89 | Critical10.0 | — | 0.6% | Aug 12, 2022 |
39Monitor | CVE-2024-48063No exploit | In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE.linuxfoundation · pytorch · CWE-502 | Critical9.8 | — | 1.6% | Oct 29, 2024 |
39Monitor | CVE-2021-39228No exploit | Memory Safety Issue when using patch or merge on state and assign the result back to statelinuxfoundation · tremor · CWE-416 | Critical9.8 | — | 1.3% | Sep 17, 2021 |
39Monitor | CVE-2022-45907No exploit | In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.linuxfoundation · pytorch · CWE-94 | Critical9.8 | — | 1.3% | Nov 25, 2022 |
39Monitor | CVE-2024-25626No exploit | Yocto Project Security Advisory - BitBake/Toasterlinuxfoundation · yocto · CWE-78 | Critical9.8 | — | 1.2% | Feb 19, 2024 |
39Monitor | CVE-2021-45701No exploit | An issue was discovered in the tremor-script crate before 0.11.6 for Rust.linuxfoundation · tremor-script · CWE-416 | Critical9.8 | — | 1.2% | Dec 26, 2021 |
39Monitor | CVE-2022-28357No exploit | NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management accoulinuxfoundation · nats-server · CWE-22 | Critical9.8 | — | 1.2% | Sep 18, 2023 |
39Monitor | CVE-2020-6174No exploit | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.linuxfoundation · the update framework · CWE-347 | Critical9.8 | — | 1.0% | Feb 5, 2020 |
39Monitor | CVE-2021-32163No exploit | Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.linuxfoundation · modular open smart network · CWE-863 | Critical9.8 | — | 0.9% | Feb 17, 2023 |
39Monitor | CVE-2024-24421No exploit | A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allowslinuxfoundation · magma · CWE-94 | Critical9.8 | — | 0.9% | Jan 21, 2025 |
39Monitor | CVE-2026-29186No exploit | @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Executionlinuxfoundation · backstage plugin-techdocs-node · CWE-74 | Critical9.8 | — | 0.9% | Mar 7, 2026 |
39Monitor | CVE-2026-35171No exploit | Arbitrary Code Execution via Malicious Logging Configuration in Kedrolinuxfoundation · kedro · CWE-94 | Critical9.8 | — | 0.9% | Apr 6, 2026 |
39Monitor | CVE-2026-37531No exploit | AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367linuxfoundation · automotive grade linux · CWE-22 | Critical9.8 | — | 0.9% | May 1, 2026 |
- CVE-2026-4532168This week
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
CriticalCVSS 9.6KEVWeaponizedEPSS 1%tanstack · tanstack\/arktype-adapterMay 11, 2026
- CVE-2019-573664This week
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
HighCVSS 8.6WeaponizedEPSS 98%docker · dockerFeb 11, 2019
- CVE-2023-2758449Plan
Dragonfly2 vulnerable to hard coded cyptographic key
CriticalCVSS 9.8Proof of conceptEPSS 34%linuxfoundation · dragonflySep 19, 2024
- CVE-2021-2345048Plan
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
CriticalCVSS 9.8No exploitEPSS 30%linuxfoundation · dojoDec 17, 2021
- CVE-2010-532541Plan
Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a den
CriticalCVSS 9.8No exploitEPSS 5%redhat · enterprise linux desktopApr 15, 2016
- CVE-2024-2162640Plan
runc container breakout through process.cwd trickery and leaked fds
HighCVSS 8.6WeaponizedEPSS 19%linuxfoundation · runcJan 31, 2024
- CVE-2019-101024540Plan
The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation.
CriticalCVSS 9.8No exploitEPSS 4%linuxfoundation · open network operating systemJul 19, 2019
- CVE-2021-4383240Plan
Improper Access Control in spinnaker
CriticalCVSS 9.8No exploitEPSS 3%linuxfoundation · spinnakerJan 4, 2022
- CVE-2020-2689240Plan
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
CriticalCVSS 9.8No exploitEPSS 2%linuxfoundation · nats-serverNov 6, 2020
- CVE-2023-3592640Plan
Insecure sandbox in Backstage Scaffolder plugin
CriticalCVSS 9.9No exploitEPSS 2%linuxfoundation · backstageJun 22, 2023
- CVE-2020-2784740Plan
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.
CriticalCVSS 9.8No exploitEPSS 2%linuxfoundation · dexMay 28, 2021
- CVE-2019-101023440Plan
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation.
CriticalCVSS 9.8No exploitEPSS 2%linuxfoundation · open network operating systemJul 22, 2019
- CVE-2022-3594240Plan
loopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filter
CriticalCVSS 10.0No exploitEPSS 1%linuxfoundation · loopback-connector-postgresqlAug 12, 2022
- CVE-2024-4806339Monitor
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE.
CriticalCVSS 9.8No exploitEPSS 2%linuxfoundation · pytorchOct 29, 2024
- CVE-2021-3922839Monitor
Memory Safety Issue when using patch or merge on state and assign the result back to state
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · tremorSep 17, 2021
- CVE-2022-4590739Monitor
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · pytorchNov 25, 2022
- CVE-2024-2562639Monitor
Yocto Project Security Advisory - BitBake/Toaster
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · yoctoFeb 19, 2024
- CVE-2021-4570139Monitor
An issue was discovered in the tremor-script crate before 0.11.6 for Rust.
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · tremor-scriptDec 26, 2021
- CVE-2022-2835739Monitor
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management accou
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · nats-serverSep 18, 2023
- CVE-2020-617439Monitor
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · the update frameworkFeb 5, 2020
- CVE-2021-3216339Monitor
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · modular open smart networkFeb 17, 2023
- CVE-2024-2442139Monitor
A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · magmaJan 21, 2025
- CVE-2026-2918639Monitor
@backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · backstage plugin-techdocs-nodeMar 7, 2026
- CVE-2026-3517139Monitor
Arbitrary Code Execution via Malicious Logging Configuration in Kedro
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · kedroApr 6, 2026
- CVE-2026-3753139Monitor
AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367
CriticalCVSS 9.8No exploitEPSS 1%linuxfoundation · automotive grade linuxMay 1, 2026