CWE-1357 · 9 kayıt
Reliance on Insufficiently Trustworthy Component
Bu sınıftaki CVE’ler
9 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2024-3313İstismar yok | SUBNET PowerSYSTEM Server and Substation Server Reliance on Insufficiently Trustworthy Componentsubnet solutions · powersystem server · CWE-1357 | Yüksek8,6 | — | %0,3 | 9 Nis 2024 |
34İzleyin | CVE-2024-26024İstismar yok | SUBNET Substation Server Reliance on Insufficiently Trustworthy Componentsubnet · substation server · CWE-1357 | Yüksek8,6 | — | %0,2 | 28 May 2024 |
34İzleyin | CVE-2024-28042İstismar yok | SUBNET PowerSYSTEM Center Reliance on Insufficiently Trustworthy Componentsubnet · powersystem center · CWE-1357 | Yüksek8,6 | — | %0,2 | 15 May 2024 |
32İzleyin | CVE-2026-47619İstismar yok | NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure.nvidia · dynamo · CWE-1357 | Yüksek8,1 | — | %0,8 | 4 Ağu 2026 |
32İzleyin | CVE-2026-85469İstismar yok | Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scopered hat · red hat quay 3 · CWE-1357 | Yüksek8,0 | — | %0,5 | 16 Eyl 2026 |
30İzleyin | CVE-2026-75569İstismar yok | Mce-operator-bundle: all github actions pinned by mutable tag, not commit shared hat · multicluster engine for kubernetes 2.1 · CWE-1357 | Yüksek7,7 | — | %0,6 | 19 Ağu 2026 |
28İzleyin | CVE-2025-32800İstismar yok | Conda-build vulnerable to supply chain attack vector due to pyproject.toml referring to dependencies not present in PyPIanaconda · conda-build · CWE-1357 | Yüksek7,2 | — | %0,6 | 16 Haz 2025 |
26İzleyin | CVE-2026-67275İstismar yok | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability.dell · powerprotect one · CWE-1357 | Orta6,5 | — | %0,3 | 26 Ağu 2026 |
17İzleyin | CVE-2026-66783İstismar yok | Submariner-operator: release workflow consumes same-org composite action via mutable @devel branch refred hat · red hat advanced cluster management for kubernetes 2.17 · CWE-1357 | Orta4,4 | — | %0,4 | 18 Ağu 2026 |
- CVE-2024-331334İzleyin
SUBNET PowerSYSTEM Server and Substation Server Reliance on Insufficiently Trustworthy Component
YüksekCVSS 8,6İstismar yokEPSS %0subnet solutions · powersystem server9 Nis 2024
- CVE-2024-2602434İzleyin
SUBNET Substation Server Reliance on Insufficiently Trustworthy Component
YüksekCVSS 8,6İstismar yokEPSS %0subnet · substation server28 May 2024
- CVE-2024-2804234İzleyin
SUBNET PowerSYSTEM Center Reliance on Insufficiently Trustworthy Component
YüksekCVSS 8,6İstismar yokEPSS %0subnet · powersystem center15 May 2024
- CVE-2026-4761932İzleyin
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure.
YüksekCVSS 8,1İstismar yokEPSS %1nvidia · dynamo4 Ağu 2026
- CVE-2026-8546932İzleyin
Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope
YüksekCVSS 8,0İstismar yokEPSS %1red hat · red hat quay 316 Eyl 2026
- CVE-2026-7556930İzleyin
Mce-operator-bundle: all github actions pinned by mutable tag, not commit sha
YüksekCVSS 7,7İstismar yokEPSS %1red hat · multicluster engine for kubernetes 2.119 Ağu 2026
- CVE-2025-3280028İzleyin
Conda-build vulnerable to supply chain attack vector due to pyproject.toml referring to dependencies not present in PyPI
YüksekCVSS 7,2İstismar yokEPSS %1anaconda · conda-build16 Haz 2025
- CVE-2026-6727526İzleyin
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability.
OrtaCVSS 6,5İstismar yokEPSS %0dell · powerprotect one26 Ağu 2026
- CVE-2026-6678317İzleyin
Submariner-operator: release workflow consumes same-org composite action via mutable @devel branch ref
OrtaCVSS 4,4İstismar yokEPSS %0red hat · red hat advanced cluster management for kubernetes 2.1718 Ağu 2026