rhmt records
5 published records for vendor rhmt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 80%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2026-9277Proof of concept | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Critical9.2 | — | 1.0% | May 22, 2026 |
34Monitor | CVE-2026-12143No exploit | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | High8.7 | — | 0.7% | Jun 12, 2026 |
30Monitor | CVE-2024-52011Proof of concept | launch-editor vulnerable to command injection via the crafted request on Windowsvitejs · launch-editor · CWE-77 | High7.5 | — | 0.5% | Jun 1, 2026 |
28Monitor | CVE-2026-0775No exploit | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm · cli · CWE-732 | High7.0 | — | 0.3% | Jan 23, 2026 |
21Monitor | CVE-2026-45292No exploit | opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagationopen-telemetry · opentelemetry-java · CWE-770 | Medium5.3 | — | 0.8% | May 28, 2026 |
- CVE-2026-927736Monitor
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
CriticalCVSS 9.2Proof of conceptEPSS 1%May 22, 2026
- CVE-2026-1214334Monitor
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
HighCVSS 8.7No exploitEPSS 1%form-data · form-dataJun 12, 2026
- CVE-2024-5201130Monitor
launch-editor vulnerable to command injection via the crafted request on Windows
HighCVSS 7.5Proof of conceptEPSS 1%vitejs · launch-editorJun 1, 2026
- CVE-2026-077528Monitor
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
HighCVSS 7.0No exploitEPSS 0%npm · cliJan 23, 2026
- CVE-2026-4529221Monitor
opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
MediumCVSS 5.3No exploitEPSS 1%open-telemetry · opentelemetry-javaMay 28, 2026