Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-49835 Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request… Sigstore Timestamp Authority 2.1.0+ Fix from $1,9502026-07-17 HIGH 7.3 CVE-2026-62290 cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing an… Cert Manager 1.19.6 / 1.20.3+ Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-55175 Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respecti… Spinnaker 2025.3.4 / 2025.4.4+ Fix from $1,9502026-07-10 HIGH 8.8 CVE-2026-44795 Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing by… Spinnaker 2025.3.3 / 2025.4.4+ Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-58208 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener c… Nats Server 2.12.12 / 2.14.3+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-58207 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send … Nats Server 2.12.12 / 2.14.3+ Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-58211 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be regi… Nats Server 2.12.12 / 2.14.3+ Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-58254 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destinati… Nats Server 2.12.8 / 2.14.3+ Fix from $1,6002026-07-08 HIGH 8.8 CVE-2026-58253 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_… Nats Server 2.11.16 / 2.12.7+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-58250 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated pee… Nats Server 2.11.17 / 2.12.8+ Fix from $1,9502026-07-08 HIGH 7.1 CVE-2026-58213 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could in… Nats Server 2.12.9 / 2.14.1+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-58251 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authentica… Nats Server 2.11.16 / 2.12.7+ Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-58252 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authentica… Nats Server 2.11.16 / 2.12.7+ Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-58210 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQT… Nats Server 2.12.12 / 2.14.3+ Fix from $1,9502026-07-08 MEDIUM 5.5 CVE-2026-44512 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.conve… Onnx 1.22.0+ Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-54712 OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, t… Opentelemetry Instrumentation For Java 2.27.0+ Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-54704 OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, t… Opentelemetry Instrumentation For Java 2.28.0+ Fix from $1,6002026-07-01 CRITICAL 9.6 CVE-2026-53492 containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Devic… Containerd 2.1.9 / 2.2.5+ Fix from $2,3002026-07-01 MEDIUM 6.5 CVE-2026-53489 containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log fr… Containerd 2.1.9 / 2.2.5+ Fix from $1,6002026-07-01 CRITICAL 9.9 CVE-2026-50195 containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process… Containerd 2.1.9 / 2.2.5+ Fix from $2,3002026-07-01 MEDIUM 5.5 CVE-2026-47262 containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a malic… Containerd 1.7.33 / 2.0.10+ Fix from $1,6002026-07-01 HIGH 7.8 CVE-2026-46680 containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directiv… Containerd 1.7.32 / 2.0.9+ Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-53488 containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an… Containerd 1.7.33 / 2.0.10+ Fix from $1,9502026-07-01 HIGH 7.1 CVE-2026-3840 A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()… Kedro No fix yet Fix from $1,9502026-06-12 CRITICAL 9.9 CVE-2026-44477 CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG met… Cloudnativepg 1.28.3 / 1.29.1+ Fix from $2,3002026-05-28 HIGH 7.4 CVE-2026-44247 Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size li… Volcano 1.12.4 / 1.13.3+ Fix from $1,9502026-05-27 HIGH 8.1 CVE-2026-41491 Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-… Dapr 1.15.14 / 1.16.14+ Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-37531 AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the … Automotive Grade Linux after 17.1.12 Fix from $2,3002026-05-01 HIGH 7.8 CVE-2026-37525 AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision Do command. The on_supervisio… Automotive Grade Linux after 17.1.12 Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-37526 AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config,… Automotive Grade Linux after 17.1.12 Fix from $1,9502026-05-01