Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-43669 A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wan… Fabric Patch available Fix from $1,9502021-11-18 HIGH 8.7 CVE-2021-41131 python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path tra… The Update Framework after 0.18.1 Fix from $1,9502021-10-19 CRITICAL 9.8 CVE-2021-39228 Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. This vulnerability is a memory … Tremor 0.11.6+ Fix from $2,3002021-09-17 MEDIUM 5.3 CVE-2021-36157 An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if craft… Cortex after 1.9.0 Fix from $1,6002021-08-03 HIGH 7.5 CVE-2021-36153 Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny service by sending malformed reques… Grpc Swift Mitigation only Fix from $1,9502021-07-09 HIGH 7.5 CVE-2021-36154 HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a si… Grpc Swift Mitigation only Fix from $1,9502021-07-09 HIGH 7.5 CVE-2021-36155 LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolle… Grpc Swift Mitigation only Fix from $1,9502021-07-09 MEDIUM 6.5 CVE-2021-32662 Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@back… Backstage 0.6.3+ Fix from $1,6002021-06-03 HIGH 7.3 CVE-2021-32661 Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.… \@backstage\/plugin Techdocs 0.9.5+ Fix from $1,9502021-06-03 HIGH 8.1 CVE-2021-32660 Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versio… \@backstage\/techdocs Common 0.6.4+ Fix from $1,9502021-06-03 CRITICAL 9.8 CVE-2020-27847 A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an atta… Dex 2.27.0+ Fix from $2,3002021-05-28 MEDIUM 5.5 CVE-2021-31232 The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP b… Cortex 1.8.1+ Fix from $1,6002021-04-30 MEDIUM 5.5 CVE-2021-29136 Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal whe… Umoci 0.4.7 / 3.7.3+ Fix from $1,6002021-04-06 HIGH 7.2 CVE-2021-20206 An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'ty… Container Network Interface 0.8.1+ Fix from $1,9502021-03-26 HIGH 7.5 CVE-2021-3127 NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled. Nats Server 2.0.1 / 2.2.0+ Fix from $1,9502021-03-16 MEDIUM 6.5 CVE-2021-21369 Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vu… Besu 1.5.1+ Fix from $1,6002021-03-09 HIGH 7.5 CVE-2020-28466 This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that repres… Nats Server 2.2.0+ Fix from $1,9502021-03-07 MEDIUM 5.3 CVE-2020-29662 In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path. Harbor 2.0.5 / 2.1.2+ Fix from $1,6002021-02-02 CRITICAL 9.6 CVE-2020-26290 Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users… Dex 2.27.0+ Fix from $2,3002020-12-28 HIGH 7.5 CVE-2020-11093 Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperledger Indy before version 1.12… Indy Node 1.12.4+ Fix from $1,9502020-12-24 MEDIUM 5.2 CVE-2020-26273 osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before version 4.6.0, by using sqlite's AT… Osquery 4.6.0+ Fix from $1,6002020-12-16 HIGH 8.8 CVE-2020-9301 Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. T… Spinnaker 1.21.5 / 1.22.4+ Fix from $1,9502020-12-11 HIGH 7.5 CVE-2020-26149 NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server. Nats.deno 1.0.0-9 / 1.0.0-111+ Fix from $1,9502020-09-30 HIGH 8.2 CVE-2020-15163 Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file w… The Update Framework 0.12.0+ Fix from $1,9502020-09-09 HIGH 7.5 CVE-2020-15687 Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in t… Acrn Mitigation only Fix from $1,9502020-08-31 HIGH 8.2 CVE-2020-11081 osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable… Osquery 4.4.0+ Fix from $1,9502020-07-10 HIGH 8.0 CVE-2020-10736 An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restri… Ceph 15.2.2+ Fix from $1,9502020-06-22 MEDIUM 5.5 CVE-2020-10750 Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. … Jaeger 1.18.1+ Fix from $1,6002020-06-19 HIGH 7.5 CVE-2020-11090 In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling code. The current primary can b… Indy Node Mitigation only Fix from $1,9502020-06-11 MEDIUM 5.3 CVE-2020-12831 An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empt… Free Range Routing after 7.3.1 Fix from $1,6002020-05-13