acm kayıtları
acm üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %76,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-190 Integer Overflow or Wraparound1
- CWE-29 Path Traversal: '\..\filename'1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-427 Uncontrolled Search Path Element1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-44990İstismar yok | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`apostrophecms · sanitize-html · CWE-79 | Kritik9,3 | — | %0,7 | 12 Haz 2026 |
34İzleyin | CVE-2026-46384İstismar yok | iskorotkov/avro: Integer Overflow in Avro Decoderiskorotkov · avro · CWE-190 | Yüksek8,7 | — | %0,9 | 29 May 2026 |
34İzleyin | CVE-2026-46385İstismar yok | iskorotkov/avro: CPU Exhaustion in Avro Decoderiskorotkov · avro · CWE-400 | Yüksek8,7 | — | %0,9 | 29 May 2026 |
34İzleyin | CVE-2026-35469İstismar yok | SpdyStream: DOS on CRImoby · spdystream · CWE-770 | Yüksek8,7 | — | %0,8 | 16 Nis 2026 |
34İzleyin | CVE-2026-12143İstismar yok | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | Yüksek8,7 | — | %0,7 | 12 Haz 2026 |
31İzleyin | CVE-2026-44724İstismar yok | systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile namesebhildebrandt · systeminformation · CWE-78 | Yüksek7,8 | — | %1,2 | 27 May 2026 |
31İzleyin | CVE-2026-11332İstismar yok | Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code executionred hat · red hat ansible automation platform 2.5 for rhel 8 · CWE-88 | Yüksek7,8 | — | %0,2 | 5 Haz 2026 |
28İzleyin | CVE-2026-0775İstismar yok | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm · cli · CWE-732 | Yüksek7,0 | — | %0,3 | 23 Oca 2026 |
28İzleyin | CVE-2026-41567Kavram kanıtı | Docker: `PUT /containers/{id}/archive` executes container binary on the hostmoby · moby/v2/daemon · CWE-427 | Yüksek7,2 | — | %0,2 | 4 Haz 2026 |
28İzleyin | CVE-2026-3006İstismar yok | Race Condition Vulnerabilitywinfsp · winfsp · CWE-362 | Yüksek7,0 | — | %0,1 | 26 Nis 2026 |
26İzleyin | CVE-2026-27145Kavram kanıtı | Inefficient candidate hostname parsing in crypto/x509go standard library · crypto/x509 · CWE-606 | Orta6,5 | — | %0,6 | 2 Haz 2026 |
22İzleyin | CVE-2026-10732İstismar yok | All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archivCWE-29 | Orta5,6 | — | %0,5 | 5 Haz 2026 |
11İzleyin | CVE-2025-69873İstismar yok | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enaajv.js · ajv · CWE-1333 | Düşük2,9 | — | %0,5 | 11 Şub 2026 |
- CVE-2026-4499037İzleyin
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
KritikCVSS 9,3İstismar yokEPSS %1apostrophecms · sanitize-html12 Haz 2026
- CVE-2026-4638434İzleyin
iskorotkov/avro: Integer Overflow in Avro Decoder
YüksekCVSS 8,7İstismar yokEPSS %1iskorotkov · avro29 May 2026
- CVE-2026-4638534İzleyin
iskorotkov/avro: CPU Exhaustion in Avro Decoder
YüksekCVSS 8,7İstismar yokEPSS %1iskorotkov · avro29 May 2026
- CVE-2026-3546934İzleyin
SpdyStream: DOS on CRI
YüksekCVSS 8,7İstismar yokEPSS %1moby · spdystream16 Nis 2026
- CVE-2026-1214334İzleyin
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
YüksekCVSS 8,7İstismar yokEPSS %1form-data · form-data12 Haz 2026
- CVE-2026-4472431İzleyin
systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name
YüksekCVSS 7,8İstismar yokEPSS %1sebhildebrandt · systeminformation27 May 2026
- CVE-2026-1133231İzleyin
Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
YüksekCVSS 7,8İstismar yokEPSS %0red hat · red hat ansible automation platform 2.5 for rhel 85 Haz 2026
- CVE-2026-077528İzleyin
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
YüksekCVSS 7,0İstismar yokEPSS %0npm · cli23 Oca 2026
- CVE-2026-4156728İzleyin
Docker: `PUT /containers/{id}/archive` executes container binary on the host
YüksekCVSS 7,2Kavram kanıtıEPSS %0moby · moby/v2/daemon4 Haz 2026
- CVE-2026-300628İzleyin
Race Condition Vulnerability
YüksekCVSS 7,0İstismar yokEPSS %0winfsp · winfsp26 Nis 2026
- CVE-2026-2714526İzleyin
Inefficient candidate hostname parsing in crypto/x509
OrtaCVSS 6,5Kavram kanıtıEPSS %1go standard library · crypto/x5092 Haz 2026
- CVE-2026-1073222İzleyin
All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archiv
OrtaCVSS 5,6İstismar yokEPSS %15 Haz 2026
- CVE-2025-6987311İzleyin
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena
DüşükCVSS 2,9İstismar yokEPSS %1ajv.js · ajv11 Şub 2026