İçeriğe atla
Noroxi

quay kayıtları

quay üreticisine ait 10 yayımlanmış kayıt.

Tüm kayıtlar

10 kayıt
  • CVE-2026-31072
    39İzleyin

    The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RC

    KritikCVSS 9,8İstismar yokEPSS %1

    19 May 2026

  • CVE-2026-44990
    37İzleyin

    Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

    KritikCVSS 9,3İstismar yokEPSS %1

    apostrophecms · sanitize-html12 Haz 2026

  • CVE-2026-9277
    36İzleyin

    shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`

    KritikCVSS 9,2Kavram kanıtıEPSS %1

    22 May 2026

  • CVE-2026-12143
    34İzleyin

    form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

    YüksekCVSS 8,7İstismar yokEPSS %1

    form-data · form-data12 Haz 2026

  • CVE-2026-1615
    32İzleyin

    Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path ex

    YüksekCVSS 8,2İstismar yokEPSS %1

    9 Şub 2026

  • CVE-2024-52011
    30İzleyin

    launch-editor vulnerable to command injection via the crafted request on Windows

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    vitejs · launch-editor1 Haz 2026

  • CVE-2026-11998
    30İzleyin

    AngularJS XSS via SCE resource URL sanitization bypass

    YüksekCVSS 7,6İstismar yokEPSS %1

    google · angularjs24 Haz 2026

  • CVE-2026-0775
    28İzleyin

    npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability

    YüksekCVSS 7,0İstismar yokEPSS %0

    npm · cli23 Oca 2026

  • CVE-2026-45292
    21İzleyin

    opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation

    OrtaCVSS 5,3İstismar yokEPSS %1

    open-telemetry · opentelemetry-java28 May 2026

  • CVE-2025-69873
    11İzleyin

    ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena

    DüşükCVSS 2,9İstismar yokEPSS %1

    ajv.js · ajv11 Şub 2026