Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Cluster Management MEDIUM 6.7
CVE-2023-2250

A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controll…

Patch available
Fix from $1,600 2023-04-24
Kubewarden Controller HIGH 8.8
CVE-2023-22645

An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get access to the ServiceAccount…

Fix: 1.6.0+
Fix from $1,950 2023-04-19
Openfeature HIGH 8.8
CVE-2023-29018

The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrar…

Fix: 0.2.32+
Fix from $1,950 2023-04-14
Cubefs MEDIUM 6.5
CVE-2023-30512

CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list a…

Fix: after 3.2.1
Fix from $1,600 2023-04-12
Runc HIGH 7.8
CVE-2023-28642

runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` in…

Fix: 1.1.5+
Fix from $1,950 2023-03-29
Runc MEDIUM 6.3
CVE-2023-25809

runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was found that rootless runc makes…

Fix: 1.1.5+
Fix from $1,600 2023-03-29
Zowe HIGH 7.8
CVE-2021-4326

A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update co…

Fix: 1.28.2 / 2.5.0+
Fix from $1,950 2023-03-01
Modular Open Smart Network CRITICAL 9.8
CVE-2021-32163

Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.

Fix: 0.23.0+
Fix from $2,300 2023-02-17
Containerd HIGH 7.8
CVE-2023-25173

containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not …

Fix: 1.5.18 / 1.6.18+
Fix from $1,950 2023-02-16
Containerd MEDIUM 5.5
CVE-2023-25153

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of b…

Fix: 1.5.18 / 1.6.18+
Fix from $1,600 2023-02-16
Backstage Catalog Model MEDIUM 5.4
CVE-2023-25571

Backstage is an open platform for building developer portals. `@backstage/catalog-model` prior to version 1.2.0, `@backstage/core-components` prior t…

Fix: 0.12.4 / 1.2.0+
Fix from $1,600 2023-02-14
Opentelemetry Go Contrib HIGH 7.5
CVE-2023-25151

opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/…

No fix yet
Fix from $1,950 2023-02-08
Onnx HIGH 7.5
CVE-2022-25882

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to th…

Fix: 1.13.0+
Fix from $1,950 2023-01-26
Zowe Api Mediation Layer MEDIUM 5.3
CVE-2021-4314

It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happ…

Fix: 1.19.0+
Fix from $1,600 2023-01-18
Harbor HIGH 7.5
CVE-2022-46463EPSS 6%

An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the…

Fix: after 2.5.3
Fix from $1,950 2023-01-13
Fossology MEDIUM 6.1
CVE-2022-4875

A vulnerability has been found in fossology and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument …

Fix: 2023-01-02+
Fix from $1,600 2023-01-04
Spinnaker HIGH 7.5
CVE-2022-23506

Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces mac…

Fix: 1.27.3 / 1.28.4+
Fix from $1,950 2023-01-03
Harbor MEDIUM 5.3
CVE-2019-19030

Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via…

Fix: 1.10.3 / 2.0.1+
Fix from $1,600 2022-12-26
Cortex MEDIUM 6.5
CVE-2022-23536

Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.1…

No fix yet
Fix from $1,600 2022-12-19
Containerd MEDIUM 6.5
CVE-2022-23471

containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In th…

Fix: 1.5.16 / 1.6.12+
Fix from $1,600 2022-12-07
Mirage Firewall HIGH 7.5
CVE-2022-46770EPSS 21%

qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and l…

Fix: 0.8.4+
Fix from $1,950 2022-12-07
Opendaylight HIGH 7.5
CVE-2022-45931

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2…

Patch available
Fix from $1,950 2022-11-27
Opendaylight HIGH 7.5
CVE-2022-45932

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2…

Patch available
Fix from $1,950 2022-11-27
Opendaylight HIGH 7.5
CVE-2022-45930

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2…

Patch available
Fix from $1,950 2022-11-27
Pytorch CRITICAL 9.8
CVE-2022-45907

In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

Fix: 1.13.1+
Fix from $2,300 2022-11-26
Knative Func HIGH 7.4
CVE-2022-41939

knative.dev/func is is a client library and CLI enabling the development and deployment of Kubernetes functions. Developers using a malicious or comp…

Fix: 1.8.1+
Fix from $1,950 2022-11-19
Kubevela MEDIUM 6.5
CVE-2022-39383

KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm C…

Fix: 1.5.9 / 1.6.2+
Fix from $1,600 2022-11-16
Software For Open Networking In The Cloud HIGH 7.5
CVE-2022-0324

There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that could cause buffer overflow i…

Mitigation only
Fix from $1,950 2022-11-14
Yocto HIGH 7.5
CVE-2022-32589

In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to remote denial of service with no…

Mitigation only
Fix from $1,950 2022-10-07
Yocto MEDIUM 6.7
CVE-2022-32590

In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution …

Mitigation only
Fix from $1,600 2022-10-07