Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Everest HIGH 7.5
CVE-2026-26008

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/…

Fix: 2026.02.0+
Fix from $1,950 2026-03-26
Everest HIGH 8.8
CVE-2026-22790

EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release bui…

Fix: 2026.02.0+
Fix from $1,950 2026-03-26
Everest HIGH 7.8
CVE-2026-22593

EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename handling causes a stack-base…

Fix: 2026.02.0+
Fix from $1,950 2026-03-26
Nats Server MEDIUM 5.4
CVE-2026-33223

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS messag…

Fix: 2.11.15 / 2.12.6+
Fix from $1,600 2026-03-25
Nats Server MEDIUM 5.4
CVE-2026-33246

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message…

Fix: 2.11.15 / 2.12.6+
Fix from $1,600 2026-03-25
Nats Server MEDIUM 5.3
CVE-2026-33247

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-serve…

Fix: 2.11.15 / 2.12.6+
Fix from $1,600 2026-03-25
Nats Server HIGH 7.5
CVE-2026-33216

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deploy…

Fix: 2.11.15 / 2.12.6+
Fix from $1,950 2026-03-25
Nats Server HIGH 7.5
CVE-2026-33218

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which …

Fix: 2.11.15 / 2.12.6+
Fix from $1,950 2026-03-25
Nats Server MEDIUM 6.5
CVE-2026-33217

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs…

Fix: 2.11.15 / 2.12.6+
Fix from $1,600 2026-03-25
Nats Server MEDIUM 5.3
CVE-2026-33219

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious cli…

Fix: 2.11.15 / 2.12.6+
Fix from $1,600 2026-03-25
Nats Server HIGH 7.5
CVE-2026-29785

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-ser…

Fix: 2.11.14 / 2.12.5+
Fix from $1,950 2026-03-25
Nats Server HIGH 7.5
CVE-2026-27889

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.…

Fix: 2.11.14 / 2.12.5+
Fix from $1,950 2026-03-25
Nats Server MEDIUM 6.5
CVE-2026-33215

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Pr…

Fix: 2.11.15 / 2.12.5+
Fix from $1,600 2026-03-24
Tekton Pipelines CRITICAL 9.6
CVE-2026-33211

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3…

Fix: 1.3.3 / 1.6.1+
Fix from $2,300 2026-03-24
Harbor CRITICAL 9.4
CVE-2026-4404

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Fix: after 2.15.0
Fix from $2,300 2026-03-23
Pytorch HIGH 7.8
CVE-2026-4538

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation …

Patch available
Fix from $1,950 2026-03-22
Tekton Pipelines MEDIUM 6.5
CVE-2026-33022

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0, 1.1.0 through 1.3.2, 1.4.0 …

Fix: 1.0.1 / 1.3.3+
Fix from $1,600 2026-03-20
Onnx CRITICAL 9.1
CVE-2026-28500

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security con…

Fix: after 1.20.1
Fix from $2,300 2026-03-18
Backstage\/plugin Scaffolder Backend MEDIUM 6.5
CVE-2026-32237

Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can…

Fix: 3.1.5+
Fix from $1,600 2026-03-12
Backstage HIGH 7.5
CVE-2026-32236

Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vulnerability exists in @backsta…

Fix: after 0.27.0
Fix from $1,950 2026-03-12
Inspektor Gadget MEDIUM 5.5
CVE-2026-31890

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior t…

Fix: 0.50.1+
Fix from $1,600 2026-03-12
Yocto HIGH 7.5
CVE-2025-61611

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed..

No fix yet
Fix from $1,950 2026-03-09
Backstage Plugin Techdocs Node CRITICAL 9.8
CVE-2026-29186

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arb…

Fix: 1.14.3+
Fix from $2,300 2026-03-07
Backstage\/plugin Scaffolder Backend MEDIUM 6.5
CVE-2026-29184

Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction m…

Fix: 3.1.4+
Fix from $1,600 2026-03-07
Vitess HIGH 8.8
CVE-2026-27969

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac…

Fix: 22.0.4 / 23.0.3+
Fix from $1,950 2026-02-26
Vitess CRITICAL 9.9
CVE-2026-27965

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac…

Fix: 22.0.4 / 23.0.3+
Fix from $2,300 2026-02-26
Nats Server HIGH 7.5
CVE-2026-27571

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles comp…

Fix: 2.11.12 / 2.12.3+
Fix from $1,950 2026-02-24
Strimzi Kafka Operator HIGH 8.1
CVE-2026-27134

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.…

Fix: 0.50.1+
Fix from $1,950 2026-02-21
Strimzi MEDIUM 5.9
CVE-2026-27133

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 to before 0.50.1, …

Fix: 0.50.1+
Fix from $1,600 2026-02-20
Inspektor Gadget CRITICAL 9.8
CVE-2026-25996

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String …

Fix: 0.49.1+
Fix from $2,300 2026-02-12