Записи Unity
3 опубликованных записей вендора unity.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 33,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
3 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
29Наблюдать | CVE-2025-59489Proof of concept | Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code funity · editor · CWE-88 | Высокая7,4 | — | 0,6 % | 3 окт. 2025 г. |
28Наблюдать | CVE-2023-37250Proof of concept | Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User"unity · parsec · CWE-367 | Высокая7,0 | — | 0,3 % | 20 авг. 2023 г. |
26Наблюдать | CVE-2015-9288Эксплойта нет | The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim'sunity · web player · CWE-200 | Средняя6,5 | — | 0,9 % | 29 июл. 2019 г. |
- CVE-2025-5948929Наблюдать
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code f
ВысокаяCVSS 7,4Proof of conceptEPSS 1 %unity · editor3 окт. 2025 г.
- CVE-2023-3725028Наблюдать
Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User"
ВысокаяCVSS 7,0Proof of conceptEPSS 0 %unity · parsec20 авг. 2023 г.
- CVE-2015-928826Наблюдать
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's
СредняяCVSS 6,5Эксплойта нетEPSS 1 %unity · web player29 июл. 2019 г.