Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Malcolm — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Malcolm, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page collects known security defects associated with the Malcolm product, classified under specific weakness categories. The database contains historical vulnerability records, covering disclosures from January 2020 through December 2023. Readers can use this page to track vendor advisories, understand the characteristics of the weakness class, and review the product's complete vulnerability history for security assessment.

Vendor: cisagov

CVE ID Title CVSS Severity Published
CVE-2026-90457 CISA Malcolm 加密问题漏洞 CWE-916 6.2 Medium 2026-09-11
CVE-2026-90456 Use of default credentials in Malcolm CWE-1392 8.1 High 2026-09-11
CVE-2026-90455 Dependency on vulnerable third-party component in Malcolm CWE-1395 3.7 Low 2026-09-11
CVE-2026-90454 Missing authorization in Malcolm CWE-862 4.3 Medium 2026-09-11
CVE-2026-90453 Open Redirect in Malcolm CWE-601 3.5 Low 2026-09-11
CVE-2026-90452 Improper certificate validation in Malcolm CWE-295 5.3 Medium 2026-09-11
CVE-2026-90451 Use of Default Credentials in Malcolm CWE-1392 5.9 Medium 2026-09-11
CVE-2026-90450 Incorrect Authorization in Malcolm CWE-863 4.3 Medium 2026-09-11
CVE-2026-90449 Missing Authentication for Critical Function in Malcolm CWE-306 6.5 Medium 2026-09-11
CVE-2026-90448 Missing Authorization in Malcolm CWE-862 6.5 Medium 2026-09-11
CVE-2026-90447 Authentication Bypass by Spoofing in Malcolm CWE-290 6.5 Medium 2026-09-11
CVE-2026-90446 Server-Side Request Forgery in Malcolm CWE-918 4.3 Medium 2026-09-11
CVE-2026-90445 Path Traversal in Malcolm CWE-22 6.5 Medium 2026-09-11
CVE-2026-90444 OS Command Injection in Malcolm CWE-78 8.8 High 2026-09-11
CVE-2026-90443 Cross-site Scripting in Malcolm CWE-79 5.4 Medium 2026-09-11
CVE-2026-19671 Improper handling of highly compressed data (data amplification) in CISA Malcolm CWE-409 6.5 Medium 2026-08-18
CVE-2026-19670 Incorrect Authorization in CISA Malcolm CWE-863 5.4 Medium 2026-08-18
CVE-2026-63177 Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBAC CWE-863 7.1 High 2026-08-11
CVE-2026-63134 Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation CWE-22 5.4 Medium 2026-08-11
CVE-2026-63133 Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS) CWE-770 6.5 Medium 2026-08-11
CVE-2026-55676 Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component CWE-434 8.8 High 2026-08-11

All 21 known CVE vulnerabilities affecting Malcolm with full Chinese analysis, references, and POCs where available.