Devscripts

Vendor:

First CVE: Jul 1, 2018 · Active for 8 years

3
Total CVEs
More Total CVEs than 64% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
9.5
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Devscripts over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2018
8 years ago
Most Recent CVE
Aug 1, 2025
357 days ago

CVE Severity & Scoring

Devscripts3 CVEs
All CVEs352,231 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (33.3%)
High0 (0.0%)
None2 (66.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Packa
Aug 1, 20259.833NONO
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unint
Jul 1, 20189.829NONO
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
Dec 3, 20198.828NONO

Exploit Exposure

Signals from CVEs in this product scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (3 CVEs).

Media Mentions

Signals from CVEs in this product scope (3 CVEs).

Top CNAs Publishing CVEs For Devscripts

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.25.1519.80.2%00