tabby kayıtları
tabby üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences1
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-45035İstismar yok | Tabby: RCE via `tabby://run` URL Schemetabby · tabby · CWE-78 | Kritik9,4 | — | %0,5 | 15 May 2026 |
33İzleyin | CVE-2026-45038İstismar yok | Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Executiontabby · tabby · CWE-150 | Yüksek8,4 | — | %0,2 | 15 May 2026 |
31İzleyin | CVE-2026-46709İstismar yok | Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)tabby · tabby · CWE-77 | Yüksek7,8 | — | %0,3 | 15 Tem 2026 |
28İzleyin | CVE-2026-45037İstismar yok | Tabby: Unsafe protocol handler execution via terminal linkifier allows arbitrary OS protocol invocationtabby · tabby · CWE-184 | Yüksek7,1 | — | %0,2 | 15 May 2026 |
28İzleyin | CVE-2026-45036İstismar yok | Tabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zshtabby · tabby · CWE-78 | Yüksek7,0 | — | %0,2 | 15 May 2026 |
- CVE-2026-4503537İzleyin
Tabby: RCE via `tabby://run` URL Scheme
KritikCVSS 9,4İstismar yokEPSS %0tabby · tabby15 May 2026
- CVE-2026-4503833İzleyin
Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution
YüksekCVSS 8,4İstismar yokEPSS %0tabby · tabby15 May 2026
- CVE-2026-4670931İzleyin
Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)
YüksekCVSS 7,8İstismar yokEPSS %0tabby · tabby15 Tem 2026
- CVE-2026-4503728İzleyin
Tabby: Unsafe protocol handler execution via terminal linkifier allows arbitrary OS protocol invocation
YüksekCVSS 7,1İstismar yokEPSS %0tabby · tabby15 May 2026
- CVE-2026-4503628İzleyin
Tabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zsh
YüksekCVSS 7,0İstismar yokEPSS %0tabby · tabby15 May 2026