jahlives
60 known vulnerabilities affecting jahlives products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-74899 | High | 0.5% | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in … | |
| CVE-2026-81690 | Medium | 0.5% | 7.3 | openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in … | |
| CVE-2026-74872 | Medium | 0.5% | 9.8 | openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulner… | |
| CVE-2026-74895 | Medium | 0.4% | 9.8 | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the … | |
| CVE-2026-74878 | Medium | 0.4% | 9.8 | openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP bru… | |
| CVE-2026-81721 | Medium | 0.4% | 7.5 | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted … | |
| CVE-2026-74886 | Medium | 0.4% | 9.8 | openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerabil… | |
| CVE-2026-74894 | Medium | 0.4% | 9.8 | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in … | |
| CVE-2026-81699 | Medium | 0.4% | 7.5 | openssl_encrypt versions before 1.4.9 fail to properly validate key derivation f… | |
| CVE-2026-81693 | Medium | 0.3% | 7.5 | openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payl… | |
| CVE-2026-74896 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in … | |
| CVE-2026-74900 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py… | |
| CVE-2026-81705 | Medium | 0.3% | 7.5 | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug ar… | |
| CVE-2026-74880 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query paramet… | |
| CVE-2026-74892 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in … | |
| CVE-2026-81719 | Medium | 0.3% | 7.8 | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insuffi… | |
| CVE-2026-81701 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-i… | |
| CVE-2026-74891 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in … | |
| CVE-2026-81698 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in… | |
| CVE-2026-74884 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in … | |
| CVE-2026-74893 | Medium | 0.3% | 8.8 | openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secr… | |
| CVE-2026-74879 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerab… | |
| CVE-2026-74883 | Medium | 0.3% | 8.8 | openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability whe… | |
| CVE-2026-74874 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random modu… | |
| CVE-2026-74877 | Medium | 0.2% | 8.8 | openssl_encrypt versions before 1.4.0 contain a missing ownership verification v… | |
| CVE-2026-81700 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerabi… | |
| CVE-2026-74901 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerabi… | |
| CVE-2026-74876 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle… | |
| CVE-2026-74889 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info para… | |
| CVE-2026-81688 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plain… | |
| CVE-2026-81689 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using un… | |
| CVE-2026-81691 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and … | |
| CVE-2026-81704 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerabilit… | |
| CVE-2026-74875 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when … | |
| CVE-2026-74888 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation c… | |
| CVE-2026-81702 | Medium | 0.1% | 9.8 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when l… | |
| CVE-2026-81714 | Medium | 0.1% | 7.0 | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fin… | |
| CVE-2026-74882 | Medium | 0.1% | 7.5 | openssl_encrypt versions before 1.4.0 contain an insecure default configuration … | |
| CVE-2026-81683 | Medium | 0.1% | 8.4 | openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store a… | |
| CVE-2026-74881 | Low | 0.3% | 6.5 | openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to w… | |
| CVE-2026-74873 | Low | 0.2% | 5.5 | openssl_encrypt versions before 1.4.0 expose passwords passed via the --password… | |
| CVE-2026-81716 | Low | 0.2% | 5.2 | openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path trav… | |
| CVE-2026-74870 | Low | 0.2% | 3.3 | openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerab… | |
| CVE-2026-81715 | Low | 0.2% | 3.3 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact th… | |
| CVE-2026-74887 | Low | 0.2% | 3.7 | openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module … | |
| CVE-2026-81685 | Low | 0.2% | 3.3 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in… | |
| CVE-2026-81694 | Low | 0.2% | 3.3 | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames rea… | |
| CVE-2026-81695 | Low | 0.2% | 3.3 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id … | |
| CVE-2026-81696 | Low | 0.2% | 3.3 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characte… | |
| CVE-2026-81703 | Low | 0.2% | 5.5 | openssl_encrypt versions before 1.4.9 fail to validate encryption status of embe… |
Page 1 of 2
Next →