Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fabric HIGH 7.5
CVE-2021-43669

A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wan…

Patch available
Fix from $1,950 2021-11-18
The Update Framework HIGH 8.7
CVE-2021-41131

python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path tra…

Fix: after 0.18.1
Fix from $1,950 2021-10-19
Tremor CRITICAL 9.8
CVE-2021-39228

Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. This vulnerability is a memory …

Fix: 0.11.6+
Fix from $2,300 2021-09-17
Cortex MEDIUM 5.3
CVE-2021-36157

An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if craft…

Fix: after 1.9.0
Fix from $1,600 2021-08-03
Grpc Swift HIGH 7.5
CVE-2021-36153

Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny service by sending malformed reques…

Mitigation only
Fix from $1,950 2021-07-09
Grpc Swift HIGH 7.5
CVE-2021-36154

HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a si…

Mitigation only
Fix from $1,950 2021-07-09
Grpc Swift HIGH 7.5
CVE-2021-36155

LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolle…

Mitigation only
Fix from $1,950 2021-07-09
Backstage MEDIUM 6.5
CVE-2021-32662

Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@back…

Fix: 0.6.3+
Fix from $1,600 2021-06-03
\@backstage\/plugin Techdocs HIGH 7.3
CVE-2021-32661

Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.…

Fix: 0.9.5+
Fix from $1,950 2021-06-03
\@backstage\/techdocs Common HIGH 8.1
CVE-2021-32660

Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versio…

Fix: 0.6.4+
Fix from $1,950 2021-06-03
Dex CRITICAL 9.8
CVE-2020-27847

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an atta…

Fix: 2.27.0+
Fix from $2,300 2021-05-28
Cortex MEDIUM 5.5
CVE-2021-31232

The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP b…

Fix: 1.8.1+
Fix from $1,600 2021-04-30
Umoci MEDIUM 5.5
CVE-2021-29136

Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal whe…

Fix: 0.4.7 / 3.7.3+
Fix from $1,600 2021-04-06
Container Network Interface HIGH 7.2
CVE-2021-20206

An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'ty…

Fix: 0.8.1+
Fix from $1,950 2021-03-26
Nats Server HIGH 7.5
CVE-2021-3127

NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.

Fix: 2.0.1 / 2.2.0+
Fix from $1,950 2021-03-16
Besu MEDIUM 6.5
CVE-2021-21369

Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vu…

Fix: 1.5.1+
Fix from $1,600 2021-03-09
Nats Server HIGH 7.5
CVE-2020-28466

This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that repres…

Fix: 2.2.0+
Fix from $1,950 2021-03-07
Harbor MEDIUM 5.3
CVE-2020-29662

In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.

Fix: 2.0.5 / 2.1.2+
Fix from $1,600 2021-02-02
Dex CRITICAL 9.6
CVE-2020-26290

Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users…

Fix: 2.27.0+
Fix from $2,300 2020-12-28
Indy Node HIGH 7.5
CVE-2020-11093

Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperledger Indy before version 1.12…

Fix: 1.12.4+
Fix from $1,950 2020-12-24
Osquery MEDIUM 5.2
CVE-2020-26273

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before version 4.6.0, by using sqlite's AT…

Fix: 4.6.0+
Fix from $1,600 2020-12-16
Spinnaker HIGH 8.8
CVE-2020-9301

Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. T…

Fix: 1.21.5 / 1.22.4+
Fix from $1,950 2020-12-11
Nats.deno HIGH 7.5
CVE-2020-26149

NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.

Fix: 1.0.0-9 / 1.0.0-111+
Fix from $1,950 2020-09-30
The Update Framework HIGH 8.2
CVE-2020-15163

Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file w…

Fix: 0.12.0+
Fix from $1,950 2020-09-09
Acrn HIGH 7.5
CVE-2020-15687

Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in t…

Mitigation only
Fix from $1,950 2020-08-31
Osquery HIGH 8.2
CVE-2020-11081

osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable…

Fix: 4.4.0+
Fix from $1,950 2020-07-10
Ceph HIGH 8.0
CVE-2020-10736

An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restri…

Fix: 15.2.2+
Fix from $1,950 2020-06-22
Jaeger MEDIUM 5.5
CVE-2020-10750

Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. …

Fix: 1.18.1+
Fix from $1,600 2020-06-19
Indy Node HIGH 7.5
CVE-2020-11090

In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling code. The current primary can b…

Mitigation only
Fix from $1,950 2020-06-11
Free Range Routing MEDIUM 5.3
CVE-2020-12831

An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empt…

Fix: after 7.3.1
Fix from $1,600 2020-05-13