openshift devspaces kayıtları
openshift devspaces üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %94,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-121 Stack-based Buffer Overflow2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-385 Covert Timing Channel1
- CWE-91 XML Injection (aka Blind XPath Injection)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-44990İstismar yok | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`apostrophecms · sanitize-html · CWE-79 | Kritik9,3 | — | %0,7 | 12 Haz 2026 |
37İzleyin | CVE-2025-14813İstismar yok | GOSTCTR implementation unable to process more than 255 blocks correctlylegion of the bouncy castle inc. · bc-java · CWE-327 | Kritik9,3 | — | %0,3 | 15 Nis 2026 |
36İzleyin | CVE-2026-9277Kavram kanıtı | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Kritik9,2 | — | %1,0 | 22 May 2026 |
35İzleyin | CVE-2026-5598İstismar yok | Non-constant time comparisons risk private key leakage in FrodoKEM.legion of the bouncy castle inc. · bc-java · CWE-385 | Yüksek8,9 | — | %1,0 | 15 Nis 2026 |
35İzleyin | CVE-2026-40611İstismar yok | Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Providergo-acme · lego · CWE-22 | Yüksek8,8 | — | %0,5 | 21 Nis 2026 |
34İzleyin | CVE-2026-1761İstismar yok | Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http responsered hat · red hat enterprise linux 10 · CWE-121 | Yüksek8,6 | — | %1,0 | 2 Şub 2026 |
34İzleyin | CVE-2026-12143İstismar yok | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | Yüksek8,7 | — | %0,7 | 12 Haz 2026 |
34İzleyin | CVE-2026-0719İstismar yok | Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authenticationred hat · red hat enterprise linux 10 · CWE-121 | Yüksek8,6 | — | %0,6 | 8 Oca 2026 |
33İzleyin | CVE-2026-0603Kavram kanıtı | Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injectionred hat · red hat jboss enterprise application platform 7.1 eus for rhel 7 · CWE-89 | Yüksek8,3 | — | %0,9 | 23 Oca 2026 |
30İzleyin | CVE-2026-40984İstismar yok | Micrometer HTTP server instrumentations DoS vulnerabilityspring · micrometer · CWE-400 | Yüksek7,5 | — | %1,1 | 9 Haz 2026 |
30İzleyin | CVE-2026-40983İstismar yok | Micrometer gRPC server instrumentation DoS vulnerabilityspring · micrometer · CWE-400 | Yüksek7,5 | — | %0,8 | 9 Haz 2026 |
30İzleyin | CVE-2026-34601İstismar yok | xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertionxmldom · xmldom · CWE-91 | Yüksek7,5 | — | %0,5 | 2 Nis 2026 |
30İzleyin | CVE-2024-52011Kavram kanıtı | launch-editor vulnerable to command injection via the crafted request on Windowsvitejs · launch-editor · CWE-77 | Yüksek7,5 | — | %0,5 | 1 Haz 2026 |
28İzleyin | CVE-2026-0775İstismar yok | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm · cli · CWE-732 | Yüksek7,0 | — | %0,3 | 23 Oca 2026 |
25İzleyin | CVE-2026-5588İstismar yok | PKIX draft CompositeVerifier accepts empty signature sequence as valid.legion of the bouncy castle inc. · bc-java · CWE-327 | Orta6,3 | — | %0,7 | 15 Nis 2026 |
22İzleyin | CVE-2026-0636İstismar yok | LDAP Injection Vulnerability in LDAPStoreHelper.javalegion of the bouncy castle inc. · bc-java · CWE-90 | Orta5,5 | — | %0,5 | 15 Nis 2026 |
21İzleyin | CVE-2026-45292İstismar yok | opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagationopen-telemetry · opentelemetry-java · CWE-770 | Orta5,3 | — | %0,8 | 28 May 2026 |
11İzleyin | CVE-2025-69873İstismar yok | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enaajv.js · ajv · CWE-1333 | Düşük2,9 | — | %0,5 | 11 Şub 2026 |
- CVE-2026-4499037İzleyin
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
KritikCVSS 9,3İstismar yokEPSS %1apostrophecms · sanitize-html12 Haz 2026
- CVE-2025-1481337İzleyin
GOSTCTR implementation unable to process more than 255 blocks correctly
KritikCVSS 9,3İstismar yokEPSS %0legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-927736İzleyin
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
KritikCVSS 9,2Kavram kanıtıEPSS %122 May 2026
- CVE-2026-559835İzleyin
Non-constant time comparisons risk private key leakage in FrodoKEM.
YüksekCVSS 8,9İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-4061135İzleyin
Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
YüksekCVSS 8,8İstismar yokEPSS %1go-acme · lego21 Nis 2026
- CVE-2026-176134İzleyin
Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response
YüksekCVSS 8,6İstismar yokEPSS %1red hat · red hat enterprise linux 102 Şub 2026
- CVE-2026-1214334İzleyin
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
YüksekCVSS 8,7İstismar yokEPSS %1form-data · form-data12 Haz 2026
- CVE-2026-071934İzleyin
Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication
YüksekCVSS 8,6İstismar yokEPSS %1red hat · red hat enterprise linux 108 Oca 2026
- CVE-2026-060333İzleyin
Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection
YüksekCVSS 8,3Kavram kanıtıEPSS %1red hat · red hat jboss enterprise application platform 7.1 eus for rhel 723 Oca 2026
- CVE-2026-4098430İzleyin
Micrometer HTTP server instrumentations DoS vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1spring · micrometer9 Haz 2026
- CVE-2026-4098330İzleyin
Micrometer gRPC server instrumentation DoS vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1spring · micrometer9 Haz 2026
- CVE-2026-3460130İzleyin
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
YüksekCVSS 7,5İstismar yokEPSS %1xmldom · xmldom2 Nis 2026
- CVE-2024-5201130İzleyin
launch-editor vulnerable to command injection via the crafted request on Windows
YüksekCVSS 7,5Kavram kanıtıEPSS %1vitejs · launch-editor1 Haz 2026
- CVE-2026-077528İzleyin
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
YüksekCVSS 7,0İstismar yokEPSS %0npm · cli23 Oca 2026
- CVE-2026-558825İzleyin
PKIX draft CompositeVerifier accepts empty signature sequence as valid.
OrtaCVSS 6,3İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-063622İzleyin
LDAP Injection Vulnerability in LDAPStoreHelper.java
OrtaCVSS 5,5İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-4529221İzleyin
opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
OrtaCVSS 5,3İstismar yokEPSS %1open-telemetry · opentelemetry-java28 May 2026
- CVE-2025-6987311İzleyin
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena
DüşükCVSS 2,9İstismar yokEPSS %1ajv.js · ajv11 Şub 2026