VYPR

blackduck-c-cpp

by Black Duck

CVEs (2)

  • CVE-2026-76055HigAug 24, 2026
    risk 0.49cvss epss

    Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able to create a file within the scanned build directory to execute operating system commands as the account running the…

  • CVE-2026-76054HigAug 24, 2026
    risk 0.46cvss epss

    Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by…