multicluster engine records
8 published records for vendor multicluster engine.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 87.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-427 Uncontrolled Search Path Element1
- CWE-606 Unchecked Input for Loop Condition1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-44990No exploit | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`apostrophecms · sanitize-html · CWE-79 | Critical9.3 | — | 0.7% | Jun 12, 2026 |
34Monitor | CVE-2026-35469No exploit | SpdyStream: DOS on CRImoby · spdystream · CWE-770 | High8.7 | — | 0.8% | Apr 16, 2026 |
34Monitor | CVE-2026-12143No exploit | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | High8.7 | — | 0.7% | Jun 12, 2026 |
31Monitor | CVE-2026-44724No exploit | systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile namesebhildebrandt · systeminformation · CWE-78 | High7.8 | — | 1.2% | May 27, 2026 |
28Monitor | CVE-2026-0775No exploit | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm · cli · CWE-732 | High7.0 | — | 0.3% | Jan 23, 2026 |
28Monitor | CVE-2026-41567Proof of concept | Docker: `PUT /containers/{id}/archive` executes container binary on the hostmoby · moby/v2/daemon · CWE-427 | High7.2 | — | 0.2% | Jun 4, 2026 |
26Monitor | CVE-2026-27145Proof of concept | Inefficient candidate hostname parsing in crypto/x509go standard library · crypto/x509 · CWE-606 | Medium6.5 | — | 0.6% | Jun 2, 2026 |
11Monitor | CVE-2025-69873No exploit | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enaajv.js · ajv · CWE-1333 | Low2.9 | — | 0.5% | Feb 11, 2026 |
- CVE-2026-4499037Monitor
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
CriticalCVSS 9.3No exploitEPSS 1%apostrophecms · sanitize-htmlJun 12, 2026
- CVE-2026-3546934Monitor
SpdyStream: DOS on CRI
HighCVSS 8.7No exploitEPSS 1%moby · spdystreamApr 16, 2026
- CVE-2026-1214334Monitor
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
HighCVSS 8.7No exploitEPSS 1%form-data · form-dataJun 12, 2026
- CVE-2026-4472431Monitor
systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name
HighCVSS 7.8No exploitEPSS 1%sebhildebrandt · systeminformationMay 27, 2026
- CVE-2026-077528Monitor
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
HighCVSS 7.0No exploitEPSS 0%npm · cliJan 23, 2026
- CVE-2026-4156728Monitor
Docker: `PUT /containers/{id}/archive` executes container binary on the host
HighCVSS 7.2Proof of conceptEPSS 0%moby · moby/v2/daemonJun 4, 2026
- CVE-2026-2714526Monitor
Inefficient candidate hostname parsing in crypto/x509
MediumCVSS 6.5Proof of conceptEPSS 1%go standard library · crypto/x509Jun 2, 2026
- CVE-2025-6987311Monitor
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena
LowCVSS 2.9No exploitEPSS 1%ajv.js · ajvFeb 11, 2026