spaceapplications records
14 published records for vendor spaceapplications.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 71.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-862 Missing Authorization1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-44596Proof of concept | Yamcs: No Rate Limiting on Authentication Endpointspaceapplications · yamcs · CWE-307 | Critical9.8 | — | 2.1% | Jul 16, 2026 |
39Monitor | CVE-2026-46562No exploit | Yamcs: Remote Code Execution via Mission Database algorithm overridespaceapplications · yamcs · CWE-94 | Critical9.8 | — | 1.0% | Jul 16, 2026 |
36Monitor | CVE-2023-45278No exploit | Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafspaceapplications · yamcs · CWE-22 | Critical9.1 | — | 1.6% | Oct 19, 2023 |
36Monitor | CVE-2026-46621No exploit | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injectionspaceapplications · yamcs · CWE-94 | Critical9.1 | — | 1.1% | Jul 16, 2026 |
36Monitor | CVE-2026-44632No exploit | Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`spaceapplications · yamcs · CWE-94 | Critical9.1 | — | 1.1% | Jul 16, 2026 |
30Monitor | CVE-2023-45277Proof of concept | Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2).spaceapplications · yamcs · CWE-22 | High7.5 | — | 1.0% | Oct 19, 2023 |
24Monitor | CVE-2023-47311No exploit | An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.spaceapplications · yacms · CWE-1021 | Medium6.1 | — | 0.4% | Nov 20, 2023 |
24Monitor | CVE-2023-45281No exploit | An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.spaceapplications · yamcs · CWE-79 | Medium6.1 | — | 0.4% | Oct 19, 2023 |
21Monitor | CVE-2023-46470No exploit | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via craftspaceapplications · yacms · CWE-79 | Medium5.4 | — | 0.6% | Nov 20, 2023 |
21Monitor | CVE-2023-46471No exploit | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the tspaceapplications · yacms · CWE-79 | Medium5.4 | — | 0.6% | Nov 20, 2023 |
21Monitor | CVE-2023-45280No exploit | Yamcs 5.8.6 allows XSS (issue 2 of 2).spaceapplications · yamcs · CWE-79 | Medium5.4 | — | 0.5% | Oct 19, 2023 |
21Monitor | CVE-2023-45279No exploit | Yamcs 5.8.6 allows XSS (issue 1 of 2).spaceapplications · yamcs · CWE-79 | Medium5.4 | — | 0.4% | Oct 19, 2023 |
17Monitor | CVE-2026-44595Proof of concept | Yamcs: Unauthorized user enumeration via IAM API endpointsspaceapplications · yamcs · CWE-862 | Medium4.3 | — | 1.1% | Jul 16, 2026 |
17Monitor | CVE-2026-55548No exploit | Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packetsspaceapplications · yamcs · CWE-284 | Medium4.3 | — | 0.4% | Jul 16, 2026 |
- CVE-2026-4459640Plan
Yamcs: No Rate Limiting on Authentication Endpoint
CriticalCVSS 9.8Proof of conceptEPSS 2%spaceapplications · yamcsJul 16, 2026
- CVE-2026-4656239Monitor
Yamcs: Remote Code Execution via Mission Database algorithm override
CriticalCVSS 9.8No exploitEPSS 1%spaceapplications · yamcsJul 16, 2026
- CVE-2023-4527836Monitor
Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via craf
CriticalCVSS 9.1No exploitEPSS 2%spaceapplications · yamcsOct 19, 2023
- CVE-2026-4662136Monitor
Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
CriticalCVSS 9.1No exploitEPSS 1%spaceapplications · yamcsJul 16, 2026
- CVE-2026-4463236Monitor
Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
CriticalCVSS 9.1No exploitEPSS 1%spaceapplications · yamcsJul 16, 2026
- CVE-2023-4527730Monitor
Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2).
HighCVSS 7.5Proof of conceptEPSS 1%spaceapplications · yamcsOct 19, 2023
- CVE-2023-4731124Monitor
An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.
MediumCVSS 6.1No exploitEPSS 0%spaceapplications · yacmsNov 20, 2023
- CVE-2023-4528124Monitor
An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.
MediumCVSS 6.1No exploitEPSS 0%spaceapplications · yamcsOct 19, 2023
- CVE-2023-4647021Monitor
Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via craft
MediumCVSS 5.4No exploitEPSS 1%spaceapplications · yacmsNov 20, 2023
- CVE-2023-4647121Monitor
Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the t
MediumCVSS 5.4No exploitEPSS 1%spaceapplications · yacmsNov 20, 2023
- CVE-2023-4528021Monitor
Yamcs 5.8.6 allows XSS (issue 2 of 2).
MediumCVSS 5.4No exploitEPSS 1%spaceapplications · yamcsOct 19, 2023
- CVE-2023-4527921Monitor
Yamcs 5.8.6 allows XSS (issue 1 of 2).
MediumCVSS 5.4No exploitEPSS 0%spaceapplications · yamcsOct 19, 2023
- CVE-2026-4459517Monitor
Yamcs: Unauthorized user enumeration via IAM API endpoints
MediumCVSS 4.3Proof of conceptEPSS 1%spaceapplications · yamcsJul 16, 2026
- CVE-2026-5554817Monitor
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
MediumCVSS 4.3No exploitEPSS 0%spaceapplications · yamcsJul 16, 2026