nhost kayıtları
nhost üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-306 Missing Authentication for Critical Function2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-343 Predictable Value Range from Previous Values1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-41574İstismar yok | Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypassnhost · nhost\/auth · CWE-287 | Kritik9,3 | — | %0,9 | 8 May 2026 |
30İzleyin | CVE-2026-34200Kavram kanıtı | Nhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network Portnhost · cli · CWE-306 | Yüksek7,7 | — | %0,6 | 31 Mar 2026 |
21İzleyin | CVE-2026-47671İstismar yok | Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secretsnhost · cli · CWE-306 | Orta5,4 | — | %0,4 | 21 Tem 2026 |
9İzleyin | CVE-2026-34969İstismar yok | Nhost Leaks the Refresh Token via URL Query Parameter in OAuth Provider Callbacknhost · nhost\/auth · CWE-200 | Düşük2,3 | — | %0,4 | 6 Nis 2026 |
8İzleyin | CVE-2026-33221İstismar yok | Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Uploadnhost · storage · CWE-343 | Düşük2,1 | — | %0,2 | 20 Mar 2026 |
- CVE-2026-4157437İzleyin
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
KritikCVSS 9,3İstismar yokEPSS %1nhost · nhost\/auth8 May 2026
- CVE-2026-3420030İzleyin
Nhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network Port
YüksekCVSS 7,7Kavram kanıtıEPSS %1nhost · cli31 Mar 2026
- CVE-2026-4767121İzleyin
Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets
OrtaCVSS 5,4İstismar yokEPSS %0nhost · cli21 Tem 2026
- CVE-2026-349699İzleyin
Nhost Leaks the Refresh Token via URL Query Parameter in OAuth Provider Callback
DüşükCVSS 2,3İstismar yokEPSS %0nhost · nhost\/auth6 Nis 2026
- CVE-2026-332218İzleyin
Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
DüşükCVSS 2,1İstismar yokEPSS %0nhost · storage20 Mar 2026