All 8 CVE vulnerabilities found in osquery, with AI-generated Chinese analysis, references, and POCs.
Vendor: Facebook
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54000 | osquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processes` table (Windows) CWE-122 | - | - | 2026-07-10 |
| CVE-2026-54001 | osquery: Heap buffer overflow via `authenticode` table (Windows) CWE-122 | - | - | 2026-07-10 |
| CVE-2026-46388 | osquery: Unprivileged users can temporarily read file carve contents CWE-279 | 4.4 | Medium | 2026-07-10 |
| CVE-2020-26273 | sqlite ATTACH allows some filesystem access CWE-77 | 5.2 | Medium | 2020-12-16 |
| CVE-2020-11081 | osquery susceptible to DLL search order hijacking of zlib1.dll CWE-114 | 5.3 | Medium | 2020-07-10 |
| CVE-2020-1887 | Facebook osquery 信任管理问题漏洞 CWE-297 | 7.4 | - | 2020-03-12 |
| CVE-2019-3567 | Facebook osquery 后置链接漏洞 CWE-284 | 9.8 | - | 2019-06-03 |
| CVE-2018-6336 | Facebook osquery 安全特征问题漏洞 CWE-254 | 7.8 | - | 2018-12-31 |
All 8 known CVE vulnerabilities affecting osquery with full Chinese analysis, references, and POCs where available.