Записи discovery
7 опубликованных записей вендора discovery.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-130 Improper Handling of Length Parameter Inconsistency1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2026-9277Proof of concept | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Критическая9,2 | — | 1,0 % | 22 мая 2026 г. |
33Наблюдать | CVE-2026-54369Эксплойта нет | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functionsacl project · acl · CWE-59 | Высокая8,4 | — | 0,2 % | 29 июн. 2026 г. |
33Наблюдать | CVE-2026-54371Эксплойта нет | attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattrattr project · attr · CWE-59 | Высокая8,4 | — | 0,2 % | 29 июн. 2026 г. |
31Наблюдать | CVE-2026-11332Эксплойта нет | Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code executionred hat · red hat ansible automation platform 2.5 for rhel 8 · CWE-88 | Высокая7,8 | — | 0,2 % | 5 июн. 2026 г. |
30Наблюдать | CVE-2026-33846Эксплойта нет | Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassemblyred hat · red hat enterprise linux 10 · CWE-130 | Высокая7,5 | — | 1,1 % | 4 мая 2026 г. |
30Наблюдать | CVE-2026-4111Эксплойта нет | Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchivered hat · red hat enterprise linux 10 · CWE-835 | Высокая7,5 | — | 0,9 % | 13 мар. 2026 г. |
30Наблюдать | CVE-2024-52011Proof of concept | launch-editor vulnerable to command injection via the crafted request on Windowsvitejs · launch-editor · CWE-77 | Высокая7,5 | — | 0,5 % | 1 июн. 2026 г. |
- CVE-2026-927736Наблюдать
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
КритическаяCVSS 9,2Proof of conceptEPSS 1 %22 мая 2026 г.
- CVE-2026-5436933Наблюдать
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %acl project · acl29 июн. 2026 г.
- CVE-2026-5437133Наблюдать
attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %attr project · attr29 июн. 2026 г.
- CVE-2026-1133231Наблюдать
Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %red hat · red hat ansible automation platform 2.5 for rhel 85 июн. 2026 г.
- CVE-2026-3384630Наблюдать
Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %red hat · red hat enterprise linux 104 мая 2026 г.
- CVE-2026-411130Наблюдать
Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %red hat · red hat enterprise linux 1013 мар. 2026 г.
- CVE-2024-5201130Наблюдать
launch-editor vulnerable to command injection via the crafted request on Windows
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %vitejs · launch-editor1 июн. 2026 г.