Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloudexplorer Lite HIGH 8.1
CVE-2023-2845

Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.

Fix: 1.1.0+
Fix from $1,950 2023-05-23
Koko CRITICAL 9.9
CVE-2023-28110

Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP serv…

Fix: 2.28.8+
Fix from $2,300 2023-03-16
Kubeoperator CRITICAL 9.8
CVE-2023-22480EPSS 67%

KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In Kube…

Fix: 3.16.4+
Fix from $2,300 2023-01-14
Kubepi HIGH 7.5
CVE-2023-22478

KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in…

Fix: 1.6.4+
Fix from $1,950 2023-01-14
Kubepi MEDIUM 6.5
CVE-2023-22479

KubePi is a modern Kubernetes panel. A session fixation attack allows an attacker to hijack a legitimate user session, versions 1.6.3 and below are s…

Fix: 1.6.4+
Fix from $1,600 2023-01-10
Kubepi CRITICAL 9.8
CVE-2023-22463EPSS 70%

KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys f…

Fix: 1.6.3+
Fix from $2,300 2023-01-04
Halo MEDIUM 5.4
CVE-2022-22123

In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can …

Fix: after 1.4.17
Fix from $1,600 2022-01-13
Halo MEDIUM 5.4
CVE-2022-22124

In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can …

Fix: after 1.4.17
Fix from $1,600 2022-01-13