Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.7
CVE-2022-32592
In cpu dvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System exec…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2022-26475
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executio…
Yocto
Mitigation only
MEDIUM 6.5
CVE-2022-39222
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clie…
Dex
2.35.0+
HIGH 7.5
CVE-2022-38817
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
Dapr Dashboard
after 0.10.0
CRITICAL 9.1
CVE-2022-36025
Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric T…
Besu
22.7.1+
HIGH 7.5
CVE-2022-31006
indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-no…
Indy Node
after 1.12.6
HIGH 8.8
CVE-2022-31020
Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` re…
Indy Node
after 1.12.4
CRITICAL 10.0
CVE-2022-35942
Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is pe…
Loopback Connector Postgresql
5.5.1+
CRITICAL 9.1
CVE-2022-34632
Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.…
Rocket Chip Generator
Patch available
MEDIUM 6.5
CVE-2022-31075
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
MEDIUM 6.5
CVE-2022-31078
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
MEDIUM 6.5
CVE-2022-31079
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
MEDIUM 6.5
CVE-2022-31080
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
HIGH 7.5
CVE-2022-31073
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
MEDIUM 6.5
CVE-2022-31074
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
MEDIUM 5.7
CVE-2022-31077
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected …
Kubeedge
1.9.3+
MEDIUM 5.7
CVE-2022-31076
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected …
Kubeedge
1.9.3+
HIGH 7.5
CVE-2022-24777
grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vuln…
Grpc Swift
1.7.2+
MEDIUM 6.5
CVE-2022-26652
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-se…
Nats Server
0.24.3 / 2.7.4+
HIGH 8.8
CVE-2022-24450
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "d…
Nats Server
0.24.1 / 2.7.2+
CRITICAL 9.8
CVE-2021-43832
Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. Thi…
Spinnaker
1.25.8 / 1.26.7+
HIGH 7.1
CVE-2021-39143
Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngin…
Spinnaker
1.24.7 / 1.25.7+
CRITICAL 9.8
CVE-2021-45701
An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A patch operation may result in a use-after-free.
Tremor Script
0.11.6+
HIGH 7.5
CVE-2021-45702
An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-free.
Tremor Script
0.11.6+
HIGH 8.1
CVE-2021-36780
A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica in…
Longhorn
1.1.3 / 1.2.3+
CRITICAL 9.6
CVE-2021-36779
A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the…
Longhorn
1.1.3 / 1.2.3+
HIGH 7.5
CVE-2021-41272
Besu is an Ethereum client written in Java. Starting in version 21.10.0, changes in the implementation of the SHL, SHR, and SAR operations resulted i…
Besu
Patch available
HIGH 8.5
CVE-2021-43783
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write a…
Backstage
0.15.14+
MEDIUM 6.1
CVE-2021-43776
Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another …
Auth Backend
0.4.9+
HIGH 7.5
CVE-2021-43667
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is …
Fabric
Patch available