📦

\

Vendor: file\

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 18 Total Indexed
Avg. EPSS 1.77% Exploit Prob.
Latest CVE CVE-2026-9538 May 26

Security Vulnerability Index

Page 2 / 2
7.8 CVSS

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

EPSS: 0.71%
7.5 CVSS

It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.

EPSS: 1.40%
7.5 CVSS

The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

EPSS: 2.00%
7.5 CVSS

The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

EPSS: 2.22%
7.5 CVSS

perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.

EPSS: 4.16%
5.9 CVSS

The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable.

EPSS: 1.34%
9.8 CVSS

SQL injection vulnerability in DBD::PgPP 0.05 and earlier

EPSS: 1.56%
5.5 CVSS

Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks

EPSS: 0.50%
9.8 CVSS

SQL injection vulnerability in Jifty::DBI before 0.68.

EPSS: 1.56%
9.8 CVSS

Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The component is: JWT.pm, line 614. The attack vector is: network connectivity. The fixed version is: after commit b98a59b42ded9f9e51b2560410106207c2152d6c.

EPSS: 1.31%