- How many CVEs does theupdateframework have?
- theupdateframework has 10 published CVE records since 2020, including 3 in the last two years.
- How many theupdateframework CVEs are in CISA KEV?
- None of theupdateframework's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
- Which theupdateframework products have the most CVEs?
- The theupdateframework products with the most published CVEs are go-tuf, tuf, github.com/theupdateframework/go-tuf/v2, python-tuf, github.com/theupdateframework/go-tuf.
- What are the most common weakness types in theupdateframework CVEs?
- theupdateframework's CVEs most often map to these CWE weakness types: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-347 (Improper Verification of Cryptographic Signature), CWE-354 (Improper Validation of Integrity Check Value), CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')).
- Are there public exploits for theupdateframework vulnerabilities?
- Yes — 1 of theupdateframework's CVEs have a known public exploit.
- How many critical theupdateframework vulnerabilities are there?
- theupdateframework has 1 critical and 5 high-severity CVEs.
- What is the average severity of theupdateframework CVEs?
- The average CVSS base score across theupdateframework's scored CVEs is 7.5.