satellite kayıtları
satellite üreticisine ait 28 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,6
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %85,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption3
- CWE-1333 Inefficient Regular Expression Complexity3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-295 Improper Certificate Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
28 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-31072İstismar yok | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCCWE-502 | Kritik9,8 | — | %1,0 | 19 May 2026 |
39İzleyin | CVE-2025-69872İstismar yok | DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default.CWE-94 | Kritik9,8 | — | %0,5 | 11 Şub 2026 |
38İzleyin | CVE-2025-24293Silahlaştırılmış | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe imagerails · activestorage · CWE-77 | Kritik9,2 | — | %5,5 | 30 Oca 2026 |
37İzleyin | CVE-2026-44990İstismar yok | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`apostrophecms · sanitize-html · CWE-79 | Kritik9,3 | — | %0,7 | 12 Haz 2026 |
37İzleyin | CVE-2025-14813İstismar yok | GOSTCTR implementation unable to process more than 255 blocks correctlylegion of the bouncy castle inc. · bc-java · CWE-327 | Kritik9,3 | — | %0,3 | 15 Nis 2026 |
36İzleyin | CVE-2026-27830İstismar yok | c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString propertyswaldman · c3p0 · CWE-94 | Yüksek8,9 | — | %2,2 | 25 Şub 2026 |
36İzleyin | CVE-2026-9277Kavram kanıtı | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Kritik9,2 | — | %1,0 | 22 May 2026 |
35İzleyin | CVE-2026-5598İstismar yok | Non-constant time comparisons risk private key leakage in FrodoKEM.legion of the bouncy castle inc. · bc-java · CWE-385 | Yüksek8,9 | — | %1,0 | 15 Nis 2026 |
34İzleyin | CVE-2026-3505İstismar yok | Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.legion of the bouncy castle inc. · bc-java · CWE-400 | Yüksek8,7 | — | %0,9 | 15 Nis 2026 |
34İzleyin | CVE-2026-33079İstismar yok | Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titleslepture · mistune · CWE-1333 | Yüksek8,7 | — | %0,7 | 6 May 2026 |
34İzleyin | CVE-2026-12143İstismar yok | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | Yüksek8,7 | — | %0,7 | 12 Haz 2026 |
34İzleyin | CVE-2026-49851İstismar yok | Mistune: Potential DoS via quadratic-time parsing in parse_link_textlepture · mistune · CWE-400 | Yüksek8,7 | — | %0,6 | 24 Haz 2026 |
33İzleyin | CVE-2026-0603Kavram kanıtı | Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injectionred hat · red hat jboss enterprise application platform 7.1 eus for rhel 7 · CWE-89 | Yüksek8,3 | — | %0,9 | 23 Oca 2026 |
32İzleyin | CVE-2026-1961Kavram kanıtı | Forman: foreman: remote code execution via command injection in websocket proxyred hat · red hat satellite 6.16 for rhel 8 · CWE-78 | Yüksek8,0 | — | %1,4 | 26 Mar 2026 |
32İzleyin | CVE-2026-1531İstismar yok | Foreman-kubevirt: foreman_kubevirt: man-in-the-middle due to insecure default ssl verificationred hat · red hat satellite 6.16 for rhel 8 · CWE-295 | Yüksek8,1 | — | %0,3 | 2 Şub 2026 |
32İzleyin | CVE-2026-1530İstismar yok | Fog-kubevirt: fog-kubevirt: man-in-the-middle vulnerability due to disabled certificate validationred hat · red hat satellite 6.16 for rhel 8 · CWE-295 | Yüksek8,1 | — | %0,3 | 2 Şub 2026 |
30İzleyin | CVE-2026-28356İstismar yok | ReDoS in multipart 1.3.0 - `parse_options_header()`defnull · multipart · CWE-1333 | Yüksek7,5 | — | %1,0 | 12 Mar 2026 |
30İzleyin | CVE-2026-40983İstismar yok | Micrometer gRPC server instrumentation DoS vulnerabilityspring · micrometer · CWE-400 | Yüksek7,5 | — | %0,8 | 9 Haz 2026 |
30İzleyin | CVE-2026-42561İstismar yok | Python-Multipart: Denial of Service via unbounded multipart part headerskludex · python-multipart · CWE-770 | Yüksek7,5 | — | %0,8 | 13 May 2026 |
30İzleyin | CVE-2026-48863İstismar yok | Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of serviceopensuse · libsolv · CWE-121 | Yüksek7,5 | — | %0,8 | 15 Tem 2026 |
28İzleyin | CVE-2026-0775İstismar yok | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm · cli · CWE-732 | Yüksek7,0 | — | %0,3 | 23 Oca 2026 |
26İzleyin | CVE-2026-27145Kavram kanıtı | Inefficient candidate hostname parsing in crypto/x509go standard library · crypto/x509 · CWE-606 | Orta6,5 | — | %0,6 | 2 Haz 2026 |
25İzleyin | CVE-2026-5588İstismar yok | PKIX draft CompositeVerifier accepts empty signature sequence as valid.legion of the bouncy castle inc. · bc-java · CWE-327 | Orta6,3 | — | %0,7 | 15 Nis 2026 |
22İzleyin | CVE-2026-0636İstismar yok | LDAP Injection Vulnerability in LDAPStoreHelper.javalegion of the bouncy castle inc. · bc-java · CWE-90 | Orta5,5 | — | %0,5 | 15 Nis 2026 |
21İzleyin | CVE-2026-45292İstismar yok | opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagationopen-telemetry · opentelemetry-java · CWE-770 | Orta5,3 | — | %0,8 | 28 May 2026 |
- CVE-2026-3107239İzleyin
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RC
KritikCVSS 9,8İstismar yokEPSS %119 May 2026
- CVE-2025-6987239İzleyin
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default.
KritikCVSS 9,8İstismar yokEPSS %111 Şub 2026
- CVE-2025-2429338İzleyin
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image
KritikCVSS 9,2SilahlaştırılmışEPSS %5rails · activestorage30 Oca 2026
- CVE-2026-4499037İzleyin
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
KritikCVSS 9,3İstismar yokEPSS %1apostrophecms · sanitize-html12 Haz 2026
- CVE-2025-1481337İzleyin
GOSTCTR implementation unable to process more than 255 blocks correctly
KritikCVSS 9,3İstismar yokEPSS %0legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-2783036İzleyin
c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
YüksekCVSS 8,9İstismar yokEPSS %2swaldman · c3p025 Şub 2026
- CVE-2026-927736İzleyin
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
KritikCVSS 9,2Kavram kanıtıEPSS %122 May 2026
- CVE-2026-559835İzleyin
Non-constant time comparisons risk private key leakage in FrodoKEM.
YüksekCVSS 8,9İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-350534İzleyin
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
YüksekCVSS 8,7İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-3307934İzleyin
Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
YüksekCVSS 8,7İstismar yokEPSS %1lepture · mistune6 May 2026
- CVE-2026-1214334İzleyin
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
YüksekCVSS 8,7İstismar yokEPSS %1form-data · form-data12 Haz 2026
- CVE-2026-4985134İzleyin
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
YüksekCVSS 8,7İstismar yokEPSS %1lepture · mistune24 Haz 2026
- CVE-2026-060333İzleyin
Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection
YüksekCVSS 8,3Kavram kanıtıEPSS %1red hat · red hat jboss enterprise application platform 7.1 eus for rhel 723 Oca 2026
- CVE-2026-196132İzleyin
Forman: foreman: remote code execution via command injection in websocket proxy
YüksekCVSS 8,0Kavram kanıtıEPSS %1red hat · red hat satellite 6.16 for rhel 826 Mar 2026
- CVE-2026-153132İzleyin
Foreman-kubevirt: foreman_kubevirt: man-in-the-middle due to insecure default ssl verification
YüksekCVSS 8,1İstismar yokEPSS %0red hat · red hat satellite 6.16 for rhel 82 Şub 2026
- CVE-2026-153032İzleyin
Fog-kubevirt: fog-kubevirt: man-in-the-middle vulnerability due to disabled certificate validation
YüksekCVSS 8,1İstismar yokEPSS %0red hat · red hat satellite 6.16 for rhel 82 Şub 2026
- CVE-2026-2835630İzleyin
ReDoS in multipart 1.3.0 - `parse_options_header()`
YüksekCVSS 7,5İstismar yokEPSS %1defnull · multipart12 Mar 2026
- CVE-2026-4098330İzleyin
Micrometer gRPC server instrumentation DoS vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1spring · micrometer9 Haz 2026
- CVE-2026-4256130İzleyin
Python-Multipart: Denial of Service via unbounded multipart part headers
YüksekCVSS 7,5İstismar yokEPSS %1kludex · python-multipart13 May 2026
- CVE-2026-4886330İzleyin
Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
YüksekCVSS 7,5İstismar yokEPSS %1opensuse · libsolv15 Tem 2026
- CVE-2026-077528İzleyin
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
YüksekCVSS 7,0İstismar yokEPSS %0npm · cli23 Oca 2026
- CVE-2026-2714526İzleyin
Inefficient candidate hostname parsing in crypto/x509
OrtaCVSS 6,5Kavram kanıtıEPSS %1go standard library · crypto/x5092 Haz 2026
- CVE-2026-558825İzleyin
PKIX draft CompositeVerifier accepts empty signature sequence as valid.
OrtaCVSS 6,3İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-063622İzleyin
LDAP Injection Vulnerability in LDAPStoreHelper.java
OrtaCVSS 5,5İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-4529221İzleyin
opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
OrtaCVSS 5,3İstismar yokEPSS %1open-telemetry · opentelemetry-java28 May 2026