netfoundry kayıtları
netfoundry üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-284 Improper Access Control1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-45568İstismar yok | zrok Python ProxyShare can be used as an SSRF proxy through absolute URL pathsnetfoundry · zrok · CWE-22 | Kritik9,9 | — | %0,5 | 16 Tem 2026 |
34İzleyin | CVE-2026-42275İstismar yok | zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/writenetfoundry · zrok · CWE-22 | Yüksek8,7 | — | %0,5 | 8 May 2026 |
33İzleyin | CVE-2026-45576İstismar yok | zrok copy writes attacker-controlled WebDAV paths outside the destination rootnetfoundry · zrok · CWE-22 | Yüksek8,3 | — | %0,5 | 16 Tem 2026 |
30İzleyin | CVE-2026-40303İstismar yok | zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsingnetfoundry · zrok · CWE-400 | Yüksek7,5 | — | %0,6 | 17 Nis 2026 |
24İzleyin | CVE-2026-40302İstismar yok | zrok has reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error renderingnetfoundry · zrok · CWE-79 | Orta6,1 | — | %0,3 | 17 Nis 2026 |
21İzleyin | CVE-2026-40304İstismar yok | zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend recordsnetfoundry · zrok · CWE-284 | Orta5,3 | — | %0,4 | 17 Nis 2026 |
- CVE-2026-4556839İzleyin
zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
KritikCVSS 9,9İstismar yokEPSS %1netfoundry · zrok16 Tem 2026
- CVE-2026-4227534İzleyin
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write
YüksekCVSS 8,7İstismar yokEPSS %0netfoundry · zrok8 May 2026
- CVE-2026-4557633İzleyin
zrok copy writes attacker-controlled WebDAV paths outside the destination root
YüksekCVSS 8,3İstismar yokEPSS %0netfoundry · zrok16 Tem 2026
- CVE-2026-4030330İzleyin
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
YüksekCVSS 7,5İstismar yokEPSS %1netfoundry · zrok17 Nis 2026
- CVE-2026-4030224İzleyin
zrok has reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
OrtaCVSS 6,1İstismar yokEPSS %0netfoundry · zrok17 Nis 2026
- CVE-2026-4030421İzleyin
zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records
OrtaCVSS 5,3İstismar yokEPSS %0netfoundry · zrok17 Nis 2026