Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Antrea CRITICAL 9.1
CVE-2026-25804

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assi…

Fix: 2.3.2 / 2.4.3+
Fix from $2,300 2026-02-06
Backstage HIGH 8.8
CVE-2026-25153

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDo…

Fix: 1.13.11 / 1.14.1+
Fix from $1,950 2026-01-30
Backstage MEDIUM 6.5
CVE-2026-25152

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDo…

Fix: 1.13.11 / 1.14.1+
Fix from $1,600 2026-01-30
Inspektor Gadget HIGH 7.8
CVE-2026-24905

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig…

Fix: 0.48.1+
Fix from $1,950 2026-01-29
Podman Desktop HIGH 7.1
CVE-2026-24835

Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnerability in Podman Desktop prio…

Fix: 1.25.1+
Fix from $1,950 2026-01-28
Pytorch HIGH 8.8
CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows a…

Fix: 2.10.0+
Fix from $1,950 2026-01-27
Sigstore Python MEDIUM 5.0
CVE-2026-24408

sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication f…

Fix: 4.2.0+
Fix from $1,600 2026-01-26
Everest MEDIUM 5.3
CVE-2026-24003

EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification includi…

Fix: after 2025.12.1
Fix from $1,600 2026-01-26
Dragonfly CRITICAL 9.8
CVE-2026-24124

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/…

Fix: 2.4.1+
Fix from $2,300 2026-01-22
Rekor MEDIUM 5.3
CVE-2026-24117

Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /ap…

Fix: 1.5.0+
Fix from $1,600 2026-01-22
Rekor MEDIUM 5.3
CVE-2026-23831

Rekor is a software supply chain transparency log. In versions 1.4.3 and below, the entry implementation can panic on attacker-controlled input when …

Fix: 1.5.0+
Fix from $1,600 2026-01-22
Everest HIGH 7.4
CVE-2025-68141

EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes` message that includes Receip…

Fix: 2025.10.0+
Fix from $1,950 2026-01-21
Everest HIGH 8.3
CVE-2025-68137

EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current…

Fix: 2025.10.0+
Fix from $1,950 2026-01-21
Everest HIGH 7.4
CVE-2025-68136

EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates a whole new set of objects l…

Fix: 2025.10.0+
Fix from $1,950 2026-01-21
Everest HIGH 7.4
CVE-2025-68134

EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors frequently causes the module …

Fix: 2025.10.0+
Fix from $1,950 2026-01-21
Everest MEDIUM 6.5
CVE-2025-68135

EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by the `TbdController` loop, le…

Fix: 2025.10.0+
Fix from $1,600 2026-01-21
Everest HIGH 7.4
CVE-2025-68133

EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's memory and cause the module …

Fix: 2025.10.0+
Fix from $1,950 2026-01-21
Fulcio MEDIUM 5.3
CVE-2026-22772

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() f…

Fix: 1.8.5+
Fix from $1,600 2026-01-12
Spinnaker MEDIUM 6.6
CVE-2025-61916

Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-si…

Fix: 2025.1.6 / 2025.2.3+
Fix from $1,600 2026-01-05
Wasmedge HIGH 7.5
CVE-2025-69261

WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causin…

Fix: 0.16.0+
Fix from $1,950 2025-12-30
Upf HIGH 7.5
CVE-2025-65566

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives …

Patch available
Fix from $1,950 2025-12-18
Gardenctl HIGH 8.4
CVE-2025-67508

gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. When using non‑POSIX shells suc…

Fix: 2.12.0+
Fix from $1,950 2025-12-12
Strimzi HIGH 7.4
CVE-2025-66623

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.…

Fix: 0.49.1+
Fix from $1,950 2025-12-05
Sigstore Timestamp Authority HIGH 7.5
CVE-2025-66564

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call…

Fix: 2.0.3+
Fix from $1,950 2025-12-04
Fulcio HIGH 7.5
CVE-2025-66506

Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function i…

Fix: 1.8.3+
Fix from $1,950 2025-12-04
Containerd MEDIUM 5.5
CVE-2025-64329

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 t…

Fix: 1.7.29 / 2.0.7+
Fix from $1,600 2025-11-07
Runc HIGH 7.5
CVE-2025-52881

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can t…

Fix: 1.2.8 / 1.3.3+
Fix from $1,950 2025-11-06
Runc HIGH 7.5
CVE-2025-52565

runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2…

Fix: 1.2.8 / 1.3.3+
Fix from $1,950 2025-11-06
Runc HIGH 7.8
CVE-2025-31133

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4…

Fix: 1.2.8 / 1.3.3+
Fix from $1,950 2025-11-06
Containerd HIGH 7.8
CVE-2024-25621

containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.…

Fix: 1.7.29 / 2.0.7+
Fix from $1,950 2025-11-06