İçeriğe atla
Noroxi

jupyter kayıtları

jupyter üreticisine ait 68 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
9
Düzeltme kaydı olan
%98,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

68 kayıt
  • CVE-2021-39159
    40Planlayın

    Remote code execution in Binderhub

    KritikCVSS 9,8İstismar yokEPSS %2

    jupyter · binderhub25 Ağu 2021

  • CVE-2026-44181
    40Planlayın

    Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution

    KritikCVSS 10,0İstismar yokEPSS %1

    jupyter · enterprise gateway16 Tem 2026

  • CVE-2026-44182
    40Planlayın

    Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering

    KritikCVSS 10,0İstismar yokEPSS %1

    jupyter · enterprise gateway16 Tem 2026

  • CVE-2021-32797
    39İzleyin

    JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

    KritikCVSS 9,6İstismar yokEPSS %3

    jupyter · jupyterlab9 Ağu 2021

  • CVE-2021-32798
    39İzleyin

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in notebook

    KritikCVSS 9,6İstismar yokEPSS %2

    jupyter · notebook9 Ağu 2021

  • CVE-2024-39700
    39İzleyin

    Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    jupyter · jupyterlab16 Tem 2024

  • CVE-2024-28179
    39İzleyin

    Jupyter Server Proxy's Websocket Proxying does not require authentication

    KritikCVSS 9,8İstismar yokEPSS %1

    jupyter · jupyter server proxy20 Mar 2024

  • CVE-2026-44180
    39İzleyin

    Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed

    KritikCVSS 9,8İstismar yokEPSS %1

    jupyter · enterprise gateway16 Tem 2026

  • CVE-2024-22415
    39İzleyin

    Unsecured endpoints in the jupyter-lsp server extension

    KritikCVSS 9,8İstismar yokEPSS %0

    jupyter · language server protocol integration18 Oca 2024

  • CVE-2023-25574
    39İzleyin

    JupyterHub's LTI13Authenticator: JWT signature not validated

    KritikCVSS 9,8İstismar yokEPSS %0

    jupyter · lti jupyterhub authenticator25 Şub 2025

  • CVE-2026-54527
    37İzleyin

    JupyterLab Git: Stored XSS leading to RCE

    KritikCVSS 9,3İstismar yokEPSS %1

    jupyter · jupyterlab-git8 Tem 2026

  • CVE-2026-44727
    37İzleyin

    Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

    KritikCVSS 9,3İstismar yokEPSS %0

    jupyter · jupyter server22 Haz 2026

  • CVE-2018-7206
    36İzleyin

    An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3.

    YüksekCVSS 8,8İstismar yokEPSS %2

    jupyter · oauthenticator17 Şub 2018

  • CVE-2024-29033
    36İzleyin

    GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace

    KritikCVSS 9,1İstismar yokEPSS %1

    jupyter · oauthenticator20 Mar 2024

  • CVE-2022-39286
    35İzleyin

    Execution with Unnecessary Privileges in JupyterApp

    YüksekCVSS 8,8İstismar yokEPSS %1

    jupyter · jupyter core26 Eki 2022

  • CVE-2022-29241
    35İzleyin

    Known or guessable hidden files may be accessed in Jupyter Server

    YüksekCVSS 8,8İstismar yokEPSS %1

    jupyter · jupyter server14 Haz 2022

  • CVE-2026-42266
    35İzleyin

    JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.

    YüksekCVSS 8,8İstismar yokEPSS %1

    jupyter · jupyterlab13 May 2026

  • CVE-2026-33175
    35İzleyin

    OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claims

    YüksekCVSS 8,8İstismar yokEPSS %1

    jupyter · oauthenticator3 Nis 2026

  • CVE-2026-6657
    35İzleyin

    CORS Origin Validation Bypass in jupyter-server

    YüksekCVSS 8,8İstismar yokEPSS %0

    jupyter · jupyter server3 Haz 2026

  • CVE-2026-42557
    34İzleyin

    jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content

    YüksekCVSS 8,6İstismar yokEPSS %1

    jupyter · jupyterlab13 May 2026

  • CVE-2025-53000
    34İzleyin

    nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows

    YüksekCVSS 8,5İstismar yokEPSS %0

    jupyter · nbconvert17 Ara 2025

  • CVE-2026-5422
    32İzleyin

    Path Traversal in jupyter/jupyter

    YüksekCVSS 8,1İstismar yokEPSS %1

    jupyter · jupyter server2 Haz 2026

  • CVE-2018-8768
    31İzleyin

    In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context.

    YüksekCVSS 7,8İstismar yokEPSS %1

    jupyter · notebook18 Mar 2018

  • CVE-2022-24757
    30İzleyin

    Sensitive Auth & Cookie data stored in Jupyter server logs

    YüksekCVSS 7,5İstismar yokEPSS %1

    jupyter · jupyter server23 Mar 2022

  • CVE-2022-24758
    30İzleyin

    Insertion of Sensitive Information into Log File affects Jupyter Notebook

    YüksekCVSS 7,5İstismar yokEPSS %1

    jupyter · notebook31 Mar 2022