İçeriğe atla
Noroxi

linuxfoundation kayıtları

linuxfoundation üreticisine ait 560 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %0,2
Silahlaştırılmış
4 · %0,7
Pre-auth RCE
27
Düzeltme kaydı olan
%56,6
Yayından KEV’e ortanca
16 gün

Tüm kayıtlar

560 kayıt
  • CVE-2026-45321
    68Bu hafta

    Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

    KritikCVSS 9,6KEVSilahlaştırılmışEPSS %1

    tanstack · tanstack\/arktype-adapter11 May 2026

  • CVE-2019-5736
    64Bu hafta

    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen

    YüksekCVSS 8,6SilahlaştırılmışEPSS %98

    docker · docker11 Şub 2019

  • CVE-2023-27584
    49Planlayın

    Dragonfly2 vulnerable to hard coded cyptographic key

    KritikCVSS 9,8Kavram kanıtıEPSS %34

    linuxfoundation · dragonfly19 Eyl 2024

  • CVE-2021-23450
    48Planlayın

    All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

    KritikCVSS 9,8İstismar yokEPSS %30

    linuxfoundation · dojo17 Ara 2021

  • CVE-2010-5325
    41Planlayın

    Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a den

    KritikCVSS 9,8İstismar yokEPSS %5

    redhat · enterprise linux desktop15 Nis 2016

  • CVE-2019-1010245
    40Planlayın

    The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation.

    KritikCVSS 9,8İstismar yokEPSS %4

    linuxfoundation · open network operating system19 Tem 2019

  • CVE-2021-43832
    40Planlayın

    Improper Access Control in spinnaker

    KritikCVSS 9,8İstismar yokEPSS %3

    linuxfoundation · spinnaker4 Oca 2022

  • CVE-2020-26892
    40Planlayın

    The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.

    KritikCVSS 9,8İstismar yokEPSS %2

    linuxfoundation · nats-server6 Kas 2020

  • CVE-2023-35926
    40Planlayın

    Insecure sandbox in Backstage Scaffolder plugin

    KritikCVSS 9,9İstismar yokEPSS %2

    linuxfoundation · backstage22 Haz 2023

  • CVE-2020-27847
    40Planlayın

    A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.

    KritikCVSS 9,8İstismar yokEPSS %2

    linuxfoundation · dex28 May 2021

  • CVE-2019-1010234
    40Planlayın

    The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation.

    KritikCVSS 9,8İstismar yokEPSS %2

    linuxfoundation · open network operating system22 Tem 2019

  • CVE-2022-35942
    40Planlayın

    loopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filter

    KritikCVSS 10,0İstismar yokEPSS %1

    linuxfoundation · loopback-connector-postgresql12 Ağu 2022

  • CVE-2024-21626
    39İzleyin

    runc container breakout through process.cwd trickery and leaked fds

    YüksekCVSS 8,6SilahlaştırılmışEPSS %18

    linuxfoundation · runc31 Oca 2024

  • CVE-2024-48063
    39İzleyin

    In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE.

    KritikCVSS 9,8İstismar yokEPSS %2

    linuxfoundation · pytorch29 Eki 2024

  • CVE-2021-39228
    39İzleyin

    Memory Safety Issue when using patch or merge on state and assign the result back to state

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · tremor17 Eyl 2021

  • CVE-2022-45907
    39İzleyin

    In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · pytorch25 Kas 2022

  • CVE-2024-25626
    39İzleyin

    Yocto Project Security Advisory - BitBake/Toaster

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · yocto19 Şub 2024

  • CVE-2021-45701
    39İzleyin

    An issue was discovered in the tremor-script crate before 0.11.6 for Rust.

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · tremor-script26 Ara 2021

  • CVE-2022-28357
    39İzleyin

    NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management accou

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · nats-server18 Eyl 2023

  • CVE-2020-6174
    39İzleyin

    TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · the update framework5 Şub 2020

  • CVE-2021-32163
    39İzleyin

    Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · modular open smart network17 Şub 2023

  • CVE-2024-24421
    39İzleyin

    A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · magma21 Oca 2025

  • CVE-2026-29186
    39İzleyin

    @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · backstage plugin-techdocs-node7 Mar 2026

  • CVE-2026-35171
    39İzleyin

    Arbitrary Code Execution via Malicious Logging Configuration in Kedro

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · kedro6 Nis 2026

  • CVE-2026-37531
    39İzleyin

    AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367

    KritikCVSS 9,8İstismar yokEPSS %1

    linuxfoundation · automotive grade linux1 May 2026