CVE Tools

Sdk

142 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Sdk, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Sdk CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Sdk CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-031
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-031
2026-042
2026-051
2026-060
2026-070
2026-080
2026-090

Severity

How the 142 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical5035%
  • High2719%
  • Medium5539%
  • Low96%

Latest CVEs

The 15 most recently published vulnerabilities affecting Sdk.

  1. CVE-2026-42190RedwoodSDK: Same-site CSRF in in server actions5.3
  2. CVE-2026-39885FrontMCP Affected by SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications7.5
  3. CVE-2026-39371RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests8.1
  4. CVE-2026-3465Tuya App/SDK JSON Data Point denial of service3.1
  5. CVE-2026-27704Dart SDK and Flutter SDK have Zip slip in Dart Pub package extraction—
  6. CVE-2025-48755In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).2.9
  7. CVE-2025-27839operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disre...3.2
  8. CVE-2024-3764Tuya SDK MQTT Packet denial of service2.7
  9. CVE-2022-40609IBM SDK, Java Technology Edition code execution8.1
  10. CVE-2019-4732IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the...6.5
  11. CVE-2018-1890IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152081.5.6
  12. CVE-2018-1656The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting...7.4
  13. CVE-2017-3210Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution7.8
  14. CVE-2017-3182On the iOS platform, the ThreatMetrix SDK versions prior to 3.2 fail to validate SSL certificates provided by HTTPS connections, which may allow an attacker to perform a man-in-the-middle (MITM) attack6.8
  15. CVE-2017-1289IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive info...8.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store