Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2024-25626
Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture…
Yocto
3.1.31 / 4.0.16+
HIGH 7.5
CVE-2024-23656
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1…
Dex
Patch available
MEDIUM 6.5
CVE-2023-46742
CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the l…
Cubefs
3.3.1+
CRITICAL 9.8
CVE-2023-46740
CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-s…
Cubefs
3.3.1+
CRITICAL 9.8
CVE-2023-46741
CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read …
Cubefs
3.3.1+
MEDIUM 5.9
CVE-2023-46739
CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1…
Cubefs
3.3.1+
MEDIUM 6.5
CVE-2023-46738
CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that c…
Cubefs
3.3.1+
MEDIUM 6.7
CVE-2023-32855
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e…
Yocto
Mitigation only
MEDIUM 6.5
CVE-2023-20902
A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below, Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with n…
Harbor
1.10.17 / 2.7.3+
HIGH 7.5
CVE-2023-46129
NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The…
Nats Server
0.4.6 / 2.10.4+
MEDIUM 6.5
CVE-2023-47090
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be …
Nats Server
2.9.23 / 2.10.2+
MEDIUM 6.7
CVE-2023-32829
In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution…
Yocto
Mitigation only
CRITICAL 9.9
CVE-2023-43632
As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port
8877 in EVE, exposing limited functionality of the TPM t…
Edge Virtualization Engine
9.5.0+
HIGH 8.8
CVE-2023-43631
On boot, the Pillar eve container checks for the existence and content of
“/config/authorized_keys”.
If the file is present, and contains a supporte…
Edge Virtualization Engine
8.6.0 / 9.5.0+
HIGH 8.8
CVE-2023-43636
In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing
the encrypted data located in the vault.
As per the “measured …
Edge Virtualization Engine
8.6.0 / 9.5.0+
HIGH 8.8
CVE-2023-43630
PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but
due to the change that was implemented in commit
“7638364bc0acf8b5c481b5ce5fea…
Edge Virtualization Engine
9.5.0+
HIGH 8.8
CVE-2023-43635
Vault Key Sealed With SHA1 PCRs
The measured boot solution implemented in EVE OS leans on a PCR locking mechanism.
Different parts of the syst…
Edge Virtualization Engine
9.5.0+
CRITICAL 9.8
CVE-2022-28357
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
Nats Server
after 2.7.4
MEDIUM 6.7
CVE-2023-32811
In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privi…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2023-32812
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with Syst…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2023-32806
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with Syste…
Yocto
Mitigation only
MEDIUM 6.4
CVE-2023-20835
In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privile…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2023-20828
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2023-20829
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2023-20830
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2023-20831
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2023-20832
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2023-20821
In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi…
Yocto
Mitigation only
MEDIUM 5.3
CVE-2023-39348
Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's…
Spinnaker
1.28.8 / 1.29.6+
MEDIUM 6.5
CVE-2023-39951
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. OpenTelemetry Java Instrumenta…
Opentelemetry Instrumentation For Java
1.28.0+