Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Automotive Grade Linux HIGH 7.5
CVE-2026-37530

AGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c alloc…

Fix: after 17.1.12
Fix from $1,950 2026-05-01
Automotive Grade Linux HIGH 7.1
CVE-2026-37532

AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_receive (receive.c:87-89), the …

Fix: after 17.1.12
Fix from $1,950 2026-05-01
Tekton Pipelines HIGH 8.5
CVE-2026-40938

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3…

Fix: 1.11.0+
Fix from $1,950 2026-04-21
Tekton Pipelines MEDIUM 6.5
CVE-2026-40924

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3…

Fix: 1.11.1+
Fix from $1,600 2026-04-21
Tekton Pipelines MEDIUM 5.4
CVE-2026-40923

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3…

Fix: 1.11.1+
Fix from $1,600 2026-04-21
Tekton Pipelines MEDIUM 6.5
CVE-2026-40161

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3…

Fix: after 1.10.0
Fix from $1,600 2026-04-21
Tekton Pipelines MEDIUM 6.5
CVE-2026-25542

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.…

Fix: 1.11.0+
Fix from $1,600 2026-04-21
Spinnaker CRITICAL 9.9
CVE-2026-32604

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor c…

Fix: 2025.3.2 / 2025.4.2+
Fix from $2,300 2026-04-20
Spinnaker CRITICAL 9.9
CVE-2026-32613

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to proce…

Fix: 2025.3.2 / 2025.4.2+
Fix from $2,300 2026-04-20
Sigstore Timestamp Authority MEDIUM 5.5
CVE-2026-39984

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in …

Fix: 2.0.6+
Fix from $1,600 2026-04-15
Podman Desktop CRITICAL 9.1
CVE-2026-34045

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des…

Fix: 1.26.2+
Fix from $2,300 2026-04-07
Kedro CRITICAL 9.8
CVE-2026-35171

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGIN…

Fix: 1.3.0+
Fix from $2,300 2026-04-06
Kedro HIGH 8.1
CVE-2026-35167

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.py constructs filesystem path…

Fix: 1.3.0+
Fix from $1,950 2026-04-06
Antrea HIGH 7.5
CVE-2026-34992

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encryption vulnerability affects int…

Fix: 2.4.5 / 2.5.2+
Fix from $1,950 2026-04-06
Onnx HIGH 8.6
CVE-2026-34445

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in…

Fix: 1.21.0+
Fix from $1,950 2026-04-01
Onnx MEDIUM 5.5
CVE-2026-34446

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.loa…

Fix: 1.21.0+
Fix from $1,600 2026-04-01
Onnx MEDIUM 5.5
CVE-2026-34447

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal …

Fix: 1.21.0+
Fix from $1,600 2026-04-01
Onnx HIGH 7.5
CVE-2026-27489

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerabilit…

Fix: 1.21.0+
Fix from $1,950 2026-04-01
Opentelemetry Instrumentation For Java CRITICAL 9.8
CVE-2026-33701

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, t…

Fix: 2.26.1+
Fix from $2,300 2026-03-27
Everest MEDIUM 5.2
CVE-2026-33015

EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop (StopTransaction), the EVSE c…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Everest MEDIUM 6.5
CVE-2026-33009

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memory corruption). This is trigg…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Everest MEDIUM 5.2
CVE-2026-33014

EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorization response restores `author…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Everest CRITICAL 9.1
CVE-2026-27815

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup copies a variable-length payment…

Fix: 2026.02.0+
Fix from $2,300 2026-03-26
Everest CRITICAL 9.1
CVE-2026-27816

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_transfer_modes copies a variable…

Fix: 2026.02.0+
Fix from $2,300 2026-03-26
Everest HIGH 7.5
CVE-2026-27828

EVerest is an EV charging software stack. Prior to version 2026.02.0, ISO15118_chargerImpl::handle_session_setup uses v2g_ctx after it has been freed…

Fix: 2026.02.0+
Fix from $1,950 2026-03-26
Everest MEDIUM 6.5
CVE-2026-29044

EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the TransactionStarted event, Au…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Everest HIGH 7.0
CVE-2026-26074

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::map<std::queue>` corruption. The tri…

Fix: 2026.02.0+
Fix from $1,950 2026-03-26
Everest MEDIUM 5.9
CVE-2026-26073

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/`std::deque` corruption. The …

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Everest MEDIUM 5.3
CVE-2026-27813

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This is triggered by EV plug-in/unp…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Everest HIGH 7.8
CVE-2026-23995

EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interfa…

Fix: 2026.02.0+
Fix from $1,950 2026-03-26