İçeriğe atla
Noroxi

rhdh kayıtları

rhdh üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%92,9
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2026-9277
    36İzleyin

    shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`

    KritikCVSS 9,2Kavram kanıtıEPSS %1

    22 May 2026

  • CVE-2026-41673
    34İzleyin

    xmldom: Denial of service via uncontrolled recursion in XML serialization

    YüksekCVSS 8,7İstismar yokEPSS %1

    xmldom · xmldom7 May 2026

  • CVE-2026-12143
    34İzleyin

    form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

    YüksekCVSS 8,7İstismar yokEPSS %1

    form-data · form-data12 Haz 2026

  • CVE-2026-41672
    34İzleyin

    xmldom: XML node injection through unvalidated comment serialization

    YüksekCVSS 8,7İstismar yokEPSS %1

    xmldom · xmldom7 May 2026

  • CVE-2026-41674
    34İzleyin

    xmldom: XML injection through unvalidated DocumentType serialization

    YüksekCVSS 8,7İstismar yokEPSS %1

    xmldom · xmldom7 May 2026

  • CVE-2026-41675
    34İzleyin

    xmldom: XML node injection through unvalidated processing instruction serialization

    YüksekCVSS 8,7İstismar yokEPSS %1

    xmldom · xmldom7 May 2026

  • CVE-2026-1615
    32İzleyin

    Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path ex

    YüksekCVSS 8,2İstismar yokEPSS %1

    9 Şub 2026

  • CVE-2026-44724
    31İzleyin

    systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name

    YüksekCVSS 7,8İstismar yokEPSS %1

    sebhildebrandt · systeminformation27 May 2026

  • CVE-2026-34601
    30İzleyin

    xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

    YüksekCVSS 7,5İstismar yokEPSS %1

    xmldom · xmldom2 Nis 2026

  • CVE-2024-52011
    30İzleyin

    launch-editor vulnerable to command injection via the crafted request on Windows

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    vitejs · launch-editor1 Haz 2026

  • CVE-2026-24046
    28İzleyin

    Backstage has a Possible Symlink Path Traversal in Scaffolder Actions

    YüksekCVSS 7,1İstismar yokEPSS %1

    backstage · backstage21 Oca 2026

  • CVE-2026-0775
    28İzleyin

    npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability

    YüksekCVSS 7,0İstismar yokEPSS %0

    npm · cli23 Oca 2026

  • CVE-2026-27145
    26İzleyin

    Inefficient candidate hostname parsing in crypto/x509

    OrtaCVSS 6,5Kavram kanıtıEPSS %1

    go standard library · crypto/x5092 Haz 2026

  • CVE-2025-69873
    11İzleyin

    ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena

    DüşükCVSS 2,9İstismar yokEPSS %1

    ajv.js · ajv11 Şub 2026