Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sigstore Timestamp Authority HIGH 7.5
CVE-2026-49835

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request…

Fix: 2.1.0+
Fix from $1,950 2026-07-17
Cert Manager HIGH 7.3
CVE-2026-62290

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing an…

Fix: 1.19.6 / 1.20.3+
Fix from $1,950 2026-07-16
Spinnaker HIGH 7.5
CVE-2026-55175

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respecti…

Fix: 2025.3.4 / 2025.4.4+
Fix from $1,950 2026-07-10
Spinnaker HIGH 8.8
CVE-2026-44795

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing by…

Fix: 2025.3.3 / 2025.4.4+
Fix from $1,950 2026-07-10
Nats Server HIGH 7.5
CVE-2026-58208

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener c…

Fix: 2.12.12 / 2.14.3+
Fix from $1,950 2026-07-08
Nats Server MEDIUM 6.5
CVE-2026-58207

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send …

Fix: 2.12.12 / 2.14.3+
Fix from $1,600 2026-07-08
Nats Server MEDIUM 5.4
CVE-2026-58211

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be regi…

Fix: 2.12.12 / 2.14.3+
Fix from $1,600 2026-07-08
Nats Server MEDIUM 6.5
CVE-2026-58254

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destinati…

Fix: 2.12.8 / 2.14.3+
Fix from $1,600 2026-07-08
Nats Server HIGH 8.8
CVE-2026-58253

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_…

Fix: 2.11.16 / 2.12.7+
Fix from $1,950 2026-07-08
Nats Server HIGH 7.5
CVE-2026-58250

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated pee…

Fix: 2.11.17 / 2.12.8+
Fix from $1,950 2026-07-08
Nats Server HIGH 7.1
CVE-2026-58213

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could in…

Fix: 2.12.9 / 2.14.1+
Fix from $1,950 2026-07-08
Nats Server MEDIUM 6.5
CVE-2026-58251

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authentica…

Fix: 2.11.16 / 2.12.7+
Fix from $1,600 2026-07-08
Nats Server MEDIUM 6.5
CVE-2026-58252

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authentica…

Fix: 2.11.16 / 2.12.7+
Fix from $1,600 2026-07-08
Nats Server HIGH 7.5
CVE-2026-58210

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQT…

Fix: 2.12.12 / 2.14.3+
Fix from $1,950 2026-07-08
Onnx MEDIUM 5.5
CVE-2026-44512

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.conve…

Fix: 1.22.0+
Fix from $1,600 2026-07-08
Opentelemetry Instrumentation For Java HIGH 7.5
CVE-2026-54712

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, t…

Fix: 2.27.0+
Fix from $1,950 2026-07-01
Opentelemetry Instrumentation For Java MEDIUM 6.5
CVE-2026-54704

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, t…

Fix: 2.28.0+
Fix from $1,600 2026-07-01
Containerd CRITICAL 9.6
CVE-2026-53492

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Devic…

Fix: 2.1.9 / 2.2.5+
Fix from $2,300 2026-07-01
Containerd MEDIUM 6.5
CVE-2026-53489

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log fr…

Fix: 2.1.9 / 2.2.5+
Fix from $1,600 2026-07-01
Containerd CRITICAL 9.9
CVE-2026-50195

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process…

Fix: 2.1.9 / 2.2.5+
Fix from $2,300 2026-07-01
Containerd MEDIUM 5.5
CVE-2026-47262

containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a malic…

Fix: 1.7.33 / 2.0.10+
Fix from $1,600 2026-07-01
Containerd HIGH 7.8
CVE-2026-46680

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directiv…

Fix: 1.7.32 / 2.0.9+
Fix from $1,950 2026-07-01
Containerd HIGH 8.8
CVE-2026-53488

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an…

Fix: 1.7.33 / 2.0.10+
Fix from $1,950 2026-07-01
Kedro HIGH 7.1
CVE-2026-3840

A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()…

No fix yet
Fix from $1,950 2026-06-12
Cloudnativepg CRITICAL 9.9
CVE-2026-44477

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG met…

Fix: 1.28.3 / 1.29.1+
Fix from $2,300 2026-05-28
Volcano HIGH 7.4
CVE-2026-44247

Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size li…

Fix: 1.12.4 / 1.13.3+
Fix from $1,950 2026-05-27
Dapr HIGH 8.1
CVE-2026-41491

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-…

Fix: 1.15.14 / 1.16.14+
Fix from $1,950 2026-05-08
Automotive Grade Linux CRITICAL 9.8
CVE-2026-37531

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the …

Fix: after 17.1.12
Fix from $2,300 2026-05-01
Automotive Grade Linux HIGH 7.8
CVE-2026-37525

AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision Do command. The on_supervisio…

Fix: after 17.1.12
Fix from $1,950 2026-05-01
Automotive Grade Linux HIGH 7.8
CVE-2026-37526

AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config,…

Fix: after 17.1.12
Fix from $1,950 2026-05-01