CVE Tools

Toolkit

9 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Toolkit, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Toolkit CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Toolkit CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-020
2025-030
2025-040
2025-050
2025-061
2025-070
2025-081
2025-091
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High338%
  • Medium450%
  • Low113%

Latest CVEs

The 9 most recently published vulnerabilities affecting Toolkit.

  1. CVE-2025-9267In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attempts to load DLLs from the current working directory without validating their...6.5
  2. CVE-2025-9043The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Se...—
  3. CVE-2025-5890actions toolkit glob internal-pattern.ts globEscape redos4.3
  4. CVE-2024-7701Misuse of SHA256 to create an encryption key7.5
  5. CVE-2024-42471Arbitrary File Write via artifact extraction in actions/artifact7.3
  6. CVE-2022-35954Delimiter injection vulnerability in @actions/core exportVariable5.0
  7. CVE-2020-15228Environment Variable Injection in GitHub Actions3.5
  8. CVE-2015-1027The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server respon...5.9
  9. CVE-2014-2029The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP ...8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store