ait-core vulnerabilities
CVEs whose affected-version data names the ait-core package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2024-35061High· 7.3NASA AIT-Core uses unencrypted channels to exchange data over the network
NASA AIT-Core uses unencrypted channels to exchange data over the network
▾ Twilightait-core · ait-coreEPSS 0.55%via OSV
CVE-2024-35059Critical· 9.8NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
▾ Midnightait-core · ait-coreEPSS 0.45%via OSV
CVE-2024-35057High· 7.5NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
▾ Twilightait-core · ait-coreEPSS 0.44%via OSV
CVE-2024-35056Critical· 9.8NASA AIT-Core vulnerable to SQL Injection
NASA AIT-Core vulnerable to SQL Injection
▾ Midnightait-core · ait-coreEPSS 0.61%via OSV
CVE-2024-35058High· 7.5NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
▾ Twilightait-core · ait-coreEPSS 0.44%via OSV