15 Total CVEs
15 AI Analyzed
0 CISA KEV
1 Critical

Profile

0% ended up actively exploited 0 of 15 added to CISA KEV
7% rated critical (CVSS 9.0+) 1 critical, 14 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

13 CVEs in the last 12 months

Products

  • CryptoLib7
  • cFS2
  • cFS (Core Flight System)2
  • earthdata-search1
  • Trick1
  • HyperCP1
  • fprime-gds1

7 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-82801
Analyzed
7.3
NASA earthdata-search

A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scal...

2026-09-01
Full analysis →
CVE-2026-82480
Analyzed
7.4
NASA cFS

A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/mod...

2026-08-30
Full analysis →
CVE-2026-82478
Analyzed
7.3
NASA Trick

A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/...

2026-08-31
Full analysis →
CVE-2026-79954
Analyzed
8.7
NASA CryptoLib

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Associ...

2026-09-19
Full analysis →
CVE-2026-72579
Analyzed
7.5
NASA HyperCP

An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from ocean...

2026-08-11
Full analysis →
CVE-2026-72577
Analyzed
9.8
NASA fprime-gds

The NASA fprime-gds application fails to implement authentication on its Flask-based endpoints, allowing unauthenticated remote attackers to execute a...

2026-08-11
Full analysis →
CVE-2026-67975
Analyzed
7.5
NASA cFS (Core Flight System)

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/...

2026-08-12
Full analysis →
CVE-2026-67974
Analyzed
7.5
NASA cFS (Core Flight System)

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause...

2026-08-27
Full analysis →
CVE-2026-67973
Analyzed
7.5
NASA cFS

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

2026-08-27
Full analysis →
CVE-2026-22697
Analyzed
7.5
NASA CryptoLib

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2026-01-10
Full analysis →
CVE-2026-21898
Analyzed
8.2
NASA CryptoLib

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2026-01-10
Full analysis →
CVE-2026-21897
Analyzed
7.3
NASA CryptoLib

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2026-01-10
Full analysis →
CVE-2025-64096
Analyzed
8.8
NASA CryptoLib

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2025-10-30
Full analysis →
CVE-2025-59534
Analyzed
7.3
NASA CryptoLib

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2025-09-23
Full analysis →
CVE-2025-54878
Analyzed
8.6
NASA CryptoLib

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2025-08-11
Full analysis →