hex kayıtları
hex üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption2
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-613 Insufficient Session Expiration1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2026-21622İstismar yok | Password Reset Tokens Do Not Expirehex · hexpm · CWE-613 | Kritik9,5 | — | %0,4 | 5 Mar 2026 |
35İzleyin | CVE-2019-1000013İstismar yok | Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can reshex · hex core · CWE-345 | Yüksek8,8 | — | %0,9 | 4 Şub 2019 |
35İzleyin | CVE-2019-1000012İstismar yok | Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result ihex · hex · CWE-345 | Yüksek8,8 | — | %0,9 | 4 Şub 2019 |
35İzleyin | CVE-2026-32148İstismar yok | Lockfile checksums not verified in Hex allows dependency integrity bypasshex · hex · CWE-354 | Yüksek8,9 | — | %0,3 | 30 Nis 2026 |
34İzleyin | CVE-2026-21618İstismar yok | Cross-site scripting (XSS) in OAuth Device Authorization screenhex · hexpm · CWE-79 | Yüksek8,5 | — | %0,3 | 19 Oca 2026 |
28İzleyin | CVE-2026-23940İstismar yok | Denial of Service via Oversized Package Uploadhex · hexpm · CWE-400 | Yüksek7,1 | — | %0,4 | 13 Mar 2026 |
28İzleyin | CVE-2026-21621İstismar yok | Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Accesshex · hexpm · CWE-863 | Yüksek7,0 | — | %0,3 | 5 Mar 2026 |
27İzleyin | CVE-2026-23939İstismar yok | Path Traversal in Local File Store Backendhex · hexpm · CWE-22 | Orta6,9 | — | %0,4 | 26 Şub 2026 |
8İzleyin | CVE-2026-21619İstismar yok | Unsafe Deserialization of Erlang Terms in hex_corehex · hex · CWE-400 | Düşük2,0 | — | %0,6 | 27 Şub 2026 |
- CVE-2026-2162238İzleyin
Password Reset Tokens Do Not Expire
KritikCVSS 9,5İstismar yokEPSS %0hex · hexpm5 Mar 2026
- CVE-2019-100001335İzleyin
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can res
YüksekCVSS 8,8İstismar yokEPSS %1hex · hex core4 Şub 2019
- CVE-2019-100001235İzleyin
Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result i
YüksekCVSS 8,8İstismar yokEPSS %1hex · hex4 Şub 2019
- CVE-2026-3214835İzleyin
Lockfile checksums not verified in Hex allows dependency integrity bypass
YüksekCVSS 8,9İstismar yokEPSS %0hex · hex30 Nis 2026
- CVE-2026-2161834İzleyin
Cross-site scripting (XSS) in OAuth Device Authorization screen
YüksekCVSS 8,5İstismar yokEPSS %0hex · hexpm19 Oca 2026
- CVE-2026-2394028İzleyin
Denial of Service via Oversized Package Upload
YüksekCVSS 7,1İstismar yokEPSS %0hex · hexpm13 Mar 2026
- CVE-2026-2162128İzleyin
Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access
YüksekCVSS 7,0İstismar yokEPSS %0hex · hexpm5 Mar 2026
- CVE-2026-2393927İzleyin
Path Traversal in Local File Store Backend
OrtaCVSS 6,9İstismar yokEPSS %0hex · hexpm26 Şub 2026
- CVE-2026-216198İzleyin
Unsafe Deserialization of Erlang Terms in hex_core
DüşükCVSS 2,0İstismar yokEPSS %1hex · hex27 Şub 2026