Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

yamcs — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting yamcs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates vulnerability data specifically for the vendor yamcs, focusing on its software products and associated security weaknesses. It collects a comprehensive range of reported security flaws, including memory corruption, input validation errors, and logic defects, covering incidents disclosed from the earliest available public records through recent updates. Readers can utilize this dataset to track the evolution of vendor advisories, analyze specific weakness classes for recurring patterns, or review the complete vulnerability history of individual yamcs components. By centralizing these entries, the aggregation provides a structured view of risk exposure over time, allowing security teams to correlate incident frequency with product versions. The collection prioritizes clarity and factual accuracy, presenting each record with standardized metadata such as severity ratings and affected version ranges. This approach supports proactive threat modeling by highlighting which areas of the yamcs codebase have historically required attention. Users should note that the data reflects publicly disclosed information and may not include zero-day exploits or unpatched internal issues. The chronological arrangement helps identify trends in vulnerability discovery and response times, offering insights into the vendor's security posture. Whether assessing supply chain risks or auditing existing deployments, this resource serves as a reference point for understanding the security landscape surrounding yamcs technologies. The focus remains strictly on technical details and historical context, excluding speculative analysis or unverified claims.

Top products by yamcs: yamcs
CVE ID Title CVSS Severity Published
CVE-2026-55566 Yamcs: DOM XSS in Extension Routing — yamcs CWE-79 4.3 Medium 2026-08-28
CVE-2026-55565 Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) — yamcs CWE-94 9.9 Critical 2026-08-28
CVE-2026-55559 Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) — yamcs CWE-94 9.8 Critical 2026-08-28
CVE-2026-55552 Yamcs: Unauthenticated Directory Traversal — yamcs CWE-22 7.5 High 2026-08-28
CVE-2026-55549 Yamcs: Reflected XSS in the URL of the Authorize Endpoint — yamcs CWE-79 6.5 Medium 2026-08-28
CVE-2026-55547 Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration — yamcs CWE-285 4.3 Medium 2026-08-28
CVE-2026-55545 Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enforce — yamcs CWE-862 6.5 Medium 2026-08-28
CVE-2026-55521 Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API — yamcs CWE-862 8.8 High 2026-08-28
CVE-2026-55511 Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` — yamcs CWE-94 9.1 Critical 2026-08-28
CVE-2026-55548 Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets — yamcs CWE-284 4.3 Medium 2026-07-16
CVE-2026-46621 Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection — yamcs CWE-94 9.1 Critical 2026-07-16
CVE-2026-46562 Yamcs: Remote Code Execution via Mission Database algorithm override — yamcs CWE-94 9.8 Critical 2026-07-16
CVE-2026-44632 Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory` — yamcs CWE-94 9.1 Critical 2026-07-16
CVE-2026-44596 Yamcs: No Rate Limiting on Authentication Endpoint — yamcs CWE-307 6.5 Medium 2026-07-16
CVE-2026-44595 Yamcs: Unauthorized user enumeration via IAM API endpoints — yamcs CWE-862 4.3 Medium 2026-07-16
CVE-2026-42568 Yamcs Vulnerable to LDAP Injection in LdapAuthModule — yamcs CWE-90 4.3 Medium 2026-06-10

This page lists every published CVE security advisory associated with yamcs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.