Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cryptolib CRITICAL 9.8
CVE-2025-29912

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication…

Fix: 1.4.0+
Fix from $2,300 2025-03-17
Cryptolib CRITICAL 9.8
CVE-2025-29913

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication…

Fix: 1.4.0+
Fix from $2,300 2025-03-17
Cryptolib CRITICAL 9.8
CVE-2025-29909

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication…

Fix: 1.4.0+
Fix from $2,300 2025-03-17
Cryptolib HIGH 7.5
CVE-2025-29910

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication…

No fix yet
Fix from $1,950 2025-03-17
Cryptolib HIGH 7.5
CVE-2024-44912

NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).

Mitigation only
Fix from $1,950 2024-09-27
Cryptolib HIGH 7.5
CVE-2024-44910

NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).

No fix yet
Fix from $1,950 2024-09-27
Cryptolib HIGH 7.5
CVE-2024-44911

NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c).

Mitigation only
Fix from $1,950 2024-09-27
Ait Core HIGH 7.5
CVE-2024-35059

An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.

Fix: after 2.5.2
Fix from $1,950 2024-05-21
Ait Core HIGH 7.5
CVE-2024-35060

An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.

Fix: after 2.5.2
Fix from $1,950 2024-05-21
Ait Core HIGH 7.3
CVE-2024-35061

NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle …

Fix: after 2.5.2
Fix from $1,950 2024-05-21
Ait Core CRITICAL 9.8
CVE-2024-35056

NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.

Fix: after 2.5.2
Fix from $2,300 2024-05-21
Ait Core HIGH 7.5
CVE-2024-35057

An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.

Fix: after 2.5.2
Fix from $1,950 2024-05-21
Ait Core HIGH 7.5
CVE-2024-35058

An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.

Fix: after 2.5.2
Fix from $1,950 2024-05-21
Openmct MEDIUM 6.5
CVE-2023-45884

Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the f…

Fix: after 3.1.0
Fix from $1,600 2023-11-09
Openmct MEDIUM 5.4
CVE-2023-45885

Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component fe…

Fix: after 3.1.0
Fix from $1,600 2023-11-09
Openmct HIGH 7.5
CVE-2023-45282

In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.

Fix: 3.1.0+
Fix from $1,950 2023-10-06
Openmct MEDIUM 6.1
CVE-2022-22126

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into …

Fix: after 1.7.7
Fix from $1,600 2022-02-20
Openmct MEDIUM 6.1
CVE-2022-23053

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScri…

Fix: after 1.7.7
Fix from $1,600 2022-02-20
Openmct MEDIUM 6.1
CVE-2022-23054

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript…

Fix: after 1.7.7
Fix from $1,600 2022-02-20
Cfitsio CRITICAL 9.8
CVE-2019-1010060EPSS 7%

NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were…

Fix: 3.43+
Fix from $2,300 2019-07-16
Cfitsio HIGH 8.8
CVE-2018-3847

Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted imag…

No fix yet
Fix from $1,950 2018-08-01
Kodiak HIGH 8.8
CVE-2018-1000047

NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This…

Mitigation only
Fix from $1,950 2018-02-09
Rtretrievalframework HIGH 8.8
CVE-2018-1000048

NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in r…

Mitigation only
Fix from $1,950 2018-02-09
Singledop HIGH 7.8
CVE-2018-1000045

NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution. This …

Patch available
Fix from $1,950 2018-02-09
Pyblock HIGH 7.8
CVE-2018-1000046

NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack…

Fix: after 1.3
Fix from $1,950 2018-02-09