jupyter kayıtları
jupyter üreticisine ait 68 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %98,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-23 Relative Path Traversal3
- CWE-20 Improper Input Validation3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
68 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-39159İstismar yok | Remote code execution in Binderhubjupyter · binderhub · CWE-94 | Kritik9,8 | — | %1,9 | 25 Ağu 2021 |
40Planlayın | CVE-2026-44181İstismar yok | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionjupyter · enterprise gateway · CWE-1336 | Kritik10,0 | — | %0,8 | 16 Tem 2026 |
40Planlayın | CVE-2026-44182İstismar yok | Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Renderingjupyter · enterprise gateway · CWE-74 | Kritik10,0 | — | %0,6 | 16 Tem 2026 |
39İzleyin | CVE-2021-32797İstismar yok | JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>jupyter · jupyterlab · CWE-79 | Kritik9,6 | — | %2,7 | 9 Ağu 2021 |
39İzleyin | CVE-2021-32798İstismar yok | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in notebookjupyter · notebook · CWE-79 | Kritik9,6 | — | %2,1 | 9 Ağu 2021 |
39İzleyin | CVE-2024-39700Kavram kanıtı | Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Actionjupyter · jupyterlab · CWE-94 | Kritik9,8 | — | %1,1 | 16 Tem 2024 |
39İzleyin | CVE-2024-28179İstismar yok | Jupyter Server Proxy's Websocket Proxying does not require authenticationjupyter · jupyter server proxy · CWE-306 | Kritik9,8 | — | %1,0 | 20 Mar 2024 |
39İzleyin | CVE-2026-44180İstismar yok | Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassedjupyter · enterprise gateway · CWE-20 | Kritik9,8 | — | %0,7 | 16 Tem 2026 |
39İzleyin | CVE-2024-22415İstismar yok | Unsecured endpoints in the jupyter-lsp server extensionjupyter · language server protocol integration · CWE-23 | Kritik9,8 | — | %0,5 | 18 Oca 2024 |
39İzleyin | CVE-2023-25574İstismar yok | JupyterHub's LTI13Authenticator: JWT signature not validatedjupyter · lti jupyterhub authenticator · CWE-347 | Kritik9,8 | — | %0,4 | 25 Şub 2025 |
37İzleyin | CVE-2026-54527İstismar yok | JupyterLab Git: Stored XSS leading to RCEjupyter · jupyterlab-git · CWE-79 | Kritik9,3 | — | %0,5 | 8 Tem 2026 |
37İzleyin | CVE-2026-44727İstismar yok | Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSPjupyter · jupyter server · CWE-79 | Kritik9,3 | — | %0,4 | 22 Haz 2026 |
36İzleyin | CVE-2018-7206İstismar yok | An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3.jupyter · oauthenticator | Yüksek8,8 | — | %1,8 | 17 Şub 2018 |
36İzleyin | CVE-2024-29033İstismar yok | GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspacejupyter · oauthenticator · CWE-285 | Kritik9,1 | — | %0,6 | 20 Mar 2024 |
35İzleyin | CVE-2022-39286İstismar yok | Execution with Unnecessary Privileges in JupyterAppjupyter · jupyter core · CWE-250 | Yüksek8,8 | — | %1,1 | 26 Eki 2022 |
35İzleyin | CVE-2022-29241İstismar yok | Known or guessable hidden files may be accessed in Jupyter Serverjupyter · jupyter server · CWE-200 | Yüksek8,8 | — | %0,9 | 14 Haz 2022 |
35İzleyin | CVE-2026-42266İstismar yok | JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.jupyter · jupyterlab · CWE-88 | Yüksek8,8 | — | %0,9 | 13 May 2026 |
35İzleyin | CVE-2026-33175İstismar yok | OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claimsjupyter · oauthenticator · CWE-287 | Yüksek8,8 | — | %0,6 | 3 Nis 2026 |
35İzleyin | CVE-2026-6657İstismar yok | CORS Origin Validation Bypass in jupyter-serverjupyter · jupyter server · CWE-346 | Yüksek8,8 | — | %0,3 | 3 Haz 2026 |
34İzleyin | CVE-2026-42557İstismar yok | jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted contentjupyter · jupyterlab · CWE-79 | Yüksek8,6 | — | %0,7 | 13 May 2026 |
34İzleyin | CVE-2025-53000İstismar yok | nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windowsjupyter · nbconvert · CWE-427 | Yüksek8,5 | — | %0,3 | 17 Ara 2025 |
32İzleyin | CVE-2026-5422İstismar yok | Path Traversal in jupyter/jupyterjupyter · jupyter server · CWE-23 | Yüksek8,1 | — | %0,5 | 2 Haz 2026 |
31İzleyin | CVE-2018-8768İstismar yok | In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context.jupyter · notebook | Yüksek7,8 | — | %1,1 | 18 Mar 2018 |
30İzleyin | CVE-2022-24757İstismar yok | Sensitive Auth & Cookie data stored in Jupyter server logsjupyter · jupyter server · CWE-532 | Yüksek7,5 | — | %1,3 | 23 Mar 2022 |
30İzleyin | CVE-2022-24758İstismar yok | Insertion of Sensitive Information into Log File affects Jupyter Notebookjupyter · notebook · CWE-532 | Yüksek7,5 | — | %1,1 | 31 Mar 2022 |
- CVE-2021-3915940Planlayın
Remote code execution in Binderhub
KritikCVSS 9,8İstismar yokEPSS %2jupyter · binderhub25 Ağu 2021
- CVE-2026-4418140Planlayın
Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution
KritikCVSS 10,0İstismar yokEPSS %1jupyter · enterprise gateway16 Tem 2026
- CVE-2026-4418240Planlayın
Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering
KritikCVSS 10,0İstismar yokEPSS %1jupyter · enterprise gateway16 Tem 2026
- CVE-2021-3279739İzleyin
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
KritikCVSS 9,6İstismar yokEPSS %3jupyter · jupyterlab9 Ağu 2021
- CVE-2021-3279839İzleyin
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in notebook
KritikCVSS 9,6İstismar yokEPSS %2jupyter · notebook9 Ağu 2021
- CVE-2024-3970039İzleyin
Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action
KritikCVSS 9,8Kavram kanıtıEPSS %1jupyter · jupyterlab16 Tem 2024
- CVE-2024-2817939İzleyin
Jupyter Server Proxy's Websocket Proxying does not require authentication
KritikCVSS 9,8İstismar yokEPSS %1jupyter · jupyter server proxy20 Mar 2024
- CVE-2026-4418039İzleyin
Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed
KritikCVSS 9,8İstismar yokEPSS %1jupyter · enterprise gateway16 Tem 2026
- CVE-2024-2241539İzleyin
Unsecured endpoints in the jupyter-lsp server extension
KritikCVSS 9,8İstismar yokEPSS %0jupyter · language server protocol integration18 Oca 2024
- CVE-2023-2557439İzleyin
JupyterHub's LTI13Authenticator: JWT signature not validated
KritikCVSS 9,8İstismar yokEPSS %0jupyter · lti jupyterhub authenticator25 Şub 2025
- CVE-2026-5452737İzleyin
JupyterLab Git: Stored XSS leading to RCE
KritikCVSS 9,3İstismar yokEPSS %1jupyter · jupyterlab-git8 Tem 2026
- CVE-2026-4472737İzleyin
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
KritikCVSS 9,3İstismar yokEPSS %0jupyter · jupyter server22 Haz 2026
- CVE-2018-720636İzleyin
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3.
YüksekCVSS 8,8İstismar yokEPSS %2jupyter · oauthenticator17 Şub 2018
- CVE-2024-2903336İzleyin
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
KritikCVSS 9,1İstismar yokEPSS %1jupyter · oauthenticator20 Mar 2024
- CVE-2022-3928635İzleyin
Execution with Unnecessary Privileges in JupyterApp
YüksekCVSS 8,8İstismar yokEPSS %1jupyter · jupyter core26 Eki 2022
- CVE-2022-2924135İzleyin
Known or guessable hidden files may be accessed in Jupyter Server
YüksekCVSS 8,8İstismar yokEPSS %1jupyter · jupyter server14 Haz 2022
- CVE-2026-4226635İzleyin
JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.
YüksekCVSS 8,8İstismar yokEPSS %1jupyter · jupyterlab13 May 2026
- CVE-2026-3317535İzleyin
OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claims
YüksekCVSS 8,8İstismar yokEPSS %1jupyter · oauthenticator3 Nis 2026
- CVE-2026-665735İzleyin
CORS Origin Validation Bypass in jupyter-server
YüksekCVSS 8,8İstismar yokEPSS %0jupyter · jupyter server3 Haz 2026
- CVE-2026-4255734İzleyin
jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content
YüksekCVSS 8,6İstismar yokEPSS %1jupyter · jupyterlab13 May 2026
- CVE-2025-5300034İzleyin
nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
YüksekCVSS 8,5İstismar yokEPSS %0jupyter · nbconvert17 Ara 2025
- CVE-2026-542232İzleyin
Path Traversal in jupyter/jupyter
YüksekCVSS 8,1İstismar yokEPSS %1jupyter · jupyter server2 Haz 2026
- CVE-2018-876831İzleyin
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context.
YüksekCVSS 7,8İstismar yokEPSS %1jupyter · notebook18 Mar 2018
- CVE-2022-2475730İzleyin
Sensitive Auth & Cookie data stored in Jupyter server logs
YüksekCVSS 7,5İstismar yokEPSS %1jupyter · jupyter server23 Mar 2022
- CVE-2022-2475830İzleyin
Insertion of Sensitive Information into Log File affects Jupyter Notebook
YüksekCVSS 7,5İstismar yokEPSS %1jupyter · notebook31 Mar 2022