Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yocto MEDIUM 6.7
CVE-2022-32592

In cpu dvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System exec…

Mitigation only
Fix from $1,600 2022-10-07
Yocto MEDIUM 6.7
CVE-2022-26475

In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executio…

Mitigation only
Fix from $1,600 2022-10-07
Dex MEDIUM 6.5
CVE-2022-39222

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clie…

Fix: 2.35.0+
Fix from $1,600 2022-10-06
Dapr Dashboard HIGH 7.5
CVE-2022-38817

Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.

Fix: after 0.10.0
Fix from $1,950 2022-10-03
Besu CRITICAL 9.1
CVE-2022-36025

Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric T…

Fix: 22.7.1+
Fix from $2,300 2022-09-24
Indy Node HIGH 7.5
CVE-2022-31006

indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-no…

Fix: after 1.12.6
Fix from $1,950 2022-09-09
Indy Node HIGH 8.8
CVE-2022-31020

Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` re…

Fix: after 1.12.4
Fix from $1,950 2022-09-06
Loopback Connector Postgresql CRITICAL 10.0
CVE-2022-35942

Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is pe…

Fix: 5.5.1+
Fix from $2,300 2022-08-12
Rocket Chip Generator CRITICAL 9.1
CVE-2022-34632

Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.…

Patch available
Fix from $2,300 2022-07-18
Kubeedge MEDIUM 6.5
CVE-2022-31075

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31078

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31079

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31080

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge HIGH 7.5
CVE-2022-31073

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,950 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31074

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 5.7
CVE-2022-31077

KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected …

Fix: 1.9.3+
Fix from $1,600 2022-06-27
Kubeedge MEDIUM 5.7
CVE-2022-31076

KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected …

Fix: 1.9.3+
Fix from $1,600 2022-06-27
Grpc Swift HIGH 7.5
CVE-2022-24777

grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vuln…

Fix: 1.7.2+
Fix from $1,950 2022-03-25
Nats Server MEDIUM 6.5
CVE-2022-26652

NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-se…

Fix: 0.24.3 / 2.7.4+
Fix from $1,600 2022-03-10
Nats Server HIGH 8.8
CVE-2022-24450

NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "d…

Fix: 0.24.1 / 2.7.2+
Fix from $1,950 2022-02-08
Spinnaker CRITICAL 9.8
CVE-2021-43832

Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. Thi…

Fix: 1.25.8 / 1.26.7+
Fix from $2,300 2022-01-04
Spinnaker HIGH 7.1
CVE-2021-39143

Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngin…

Fix: 1.24.7 / 1.25.7+
Fix from $1,950 2022-01-04
Tremor Script CRITICAL 9.8
CVE-2021-45701

An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A patch operation may result in a use-after-free.

Fix: 0.11.6+
Fix from $2,300 2021-12-27
Tremor Script HIGH 7.5
CVE-2021-45702

An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-free.

Fix: 0.11.6+
Fix from $1,950 2021-12-27
Longhorn HIGH 8.1
CVE-2021-36780

A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica in…

Fix: 1.1.3 / 1.2.3+
Fix from $1,950 2021-12-17
Longhorn CRITICAL 9.6
CVE-2021-36779

A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the…

Fix: 1.1.3 / 1.2.3+
Fix from $2,300 2021-12-17
Besu HIGH 7.5
CVE-2021-41272

Besu is an Ethereum client written in Java. Starting in version 21.10.0, changes in the implementation of the SHL, SHR, and SAR operations resulted i…

Patch available
Fix from $1,950 2021-12-13
Backstage HIGH 8.5
CVE-2021-43783

@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write a…

Fix: 0.15.14+
Fix from $1,950 2021-11-29
Auth Backend MEDIUM 6.1
CVE-2021-43776

Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another …

Fix: 0.4.9+
Fix from $1,600 2021-11-26
Fabric HIGH 7.5
CVE-2021-43667

A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is …

Patch available
Fix from $1,950 2021-11-18