İçeriğe atla
Noroxi

openshift devspaces kayıtları

openshift devspaces üreticisine ait 18 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%94,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

18 kayıt
  • CVE-2026-44990
    37İzleyin

    Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

    KritikCVSS 9,3İstismar yokEPSS %1

    apostrophecms · sanitize-html12 Haz 2026

  • CVE-2025-14813
    37İzleyin

    GOSTCTR implementation unable to process more than 255 blocks correctly

    KritikCVSS 9,3İstismar yokEPSS %0

    legion of the bouncy castle inc. · bc-java15 Nis 2026

  • CVE-2026-9277
    36İzleyin

    shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`

    KritikCVSS 9,2Kavram kanıtıEPSS %1

    22 May 2026

  • CVE-2026-5598
    35İzleyin

    Non-constant time comparisons risk private key leakage in FrodoKEM.

    YüksekCVSS 8,9İstismar yokEPSS %1

    legion of the bouncy castle inc. · bc-java15 Nis 2026

  • CVE-2026-40611
    35İzleyin

    Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider

    YüksekCVSS 8,8İstismar yokEPSS %1

    go-acme · lego21 Nis 2026

  • CVE-2026-1761
    34İzleyin

    Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response

    YüksekCVSS 8,6İstismar yokEPSS %1

    red hat · red hat enterprise linux 102 Şub 2026

  • CVE-2026-12143
    34İzleyin

    form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

    YüksekCVSS 8,7İstismar yokEPSS %1

    form-data · form-data12 Haz 2026

  • CVE-2026-0719
    34İzleyin

    Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication

    YüksekCVSS 8,6İstismar yokEPSS %1

    red hat · red hat enterprise linux 108 Oca 2026

  • CVE-2026-0603
    33İzleyin

    Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection

    YüksekCVSS 8,3Kavram kanıtıEPSS %1

    red hat · red hat jboss enterprise application platform 7.1 eus for rhel 723 Oca 2026

  • CVE-2026-40984
    30İzleyin

    Micrometer HTTP server instrumentations DoS vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %1

    spring · micrometer9 Haz 2026

  • CVE-2026-40983
    30İzleyin

    Micrometer gRPC server instrumentation DoS vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %1

    spring · micrometer9 Haz 2026

  • CVE-2026-34601
    30İzleyin

    xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

    YüksekCVSS 7,5İstismar yokEPSS %1

    xmldom · xmldom2 Nis 2026

  • CVE-2024-52011
    30İzleyin

    launch-editor vulnerable to command injection via the crafted request on Windows

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    vitejs · launch-editor1 Haz 2026

  • CVE-2026-0775
    28İzleyin

    npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability

    YüksekCVSS 7,0İstismar yokEPSS %0

    npm · cli23 Oca 2026

  • CVE-2026-5588
    25İzleyin

    PKIX draft CompositeVerifier accepts empty signature sequence as valid.

    OrtaCVSS 6,3İstismar yokEPSS %1

    legion of the bouncy castle inc. · bc-java15 Nis 2026

  • CVE-2026-0636
    22İzleyin

    LDAP Injection Vulnerability in LDAPStoreHelper.java

    OrtaCVSS 5,5İstismar yokEPSS %1

    legion of the bouncy castle inc. · bc-java15 Nis 2026

  • CVE-2026-45292
    21İzleyin

    opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation

    OrtaCVSS 5,3İstismar yokEPSS %1

    open-telemetry · opentelemetry-java28 May 2026

  • CVE-2025-69873
    11İzleyin

    ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena

    DüşükCVSS 2,9İstismar yokEPSS %1

    ajv.js · ajv11 Şub 2026