VYPR

Vendor CVEs

Helm

All CVEs

55 total · sorted by risk
  • CVE-2026-32968CriMar 23, 2026
    risk 0.64cvss 9.8epss 0.01

    Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.

  • CVE-2024-45275CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.

  • CVE-2024-45274CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.02

    An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

  • CVE-2019-18658CriNov 12, 2019
    risk 0.64cvss 9.8epss 0.02

    In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a special file such as…

  • CVE-2023-0985HigJun 6, 2023
    risk 0.57cvss 8.8epss 0.01

    An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to…

  • CVE-2019-1010275CriJul 17, 2019
    risk 0.57cvss 9.8epss 0.01

    helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were aloowed. The component is: helm (many files updated, see https://github.com/helm/helm/pull/3152/files/…

  • CVE-2024-45273HigOct 15, 2024
    risk 0.55cvss 8.4epss 0.00

    An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

  • CVE-2024-45271HigOct 15, 2024
    risk 0.55cvss 8.4epss 0.00

    An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

  • CVE-2022-36049HigSep 7, 2022
    risk 0.50cvss 7.7epss 0.01

    Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is tightly integrated with the Helm SDK. A vulnerability found…

  • CVE-2026-35204HigApr 9, 2026
    risk 0.49cvss 8.6epss 0.00

    Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the…

  • CVE-2026-32969HigMar 23, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

  • CVE-2024-45276HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

  • CVE-2024-45272HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.

  • CVE-2020-35558HigFeb 16, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.

  • CVE-2025-53547HigJul 8, 2025
    risk 0.48cvss 8.5epss 0.00

    Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a…

  • CVE-2026-35205HigApr 9, 2026
    risk 0.44cvss 7.8epss 0.00

    Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.

  • CVE-2019-25210MedMar 3, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that…

  • CVE-2024-26147HigFeb 21, 2024
    risk 0.42cvss 7.5epss 0.01

    Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all…

  • CVE-2020-12527MedMar 2, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding…

  • CVE-2020-35557MedFeb 16, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.

  • CVE-2019-1000009MedFeb 4, 2019
    risk 0.42cvss 6.5epss 0.01

    Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HTTP API to save charts that can result in a specially crafted chart could be uploaded and saved outside the intended…

  • CVE-2019-1000008MedFeb 4, 2019
    risk 0.42cvss 6.5epss 0.01

    All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The commands `helm fetch --untar` and `helm lint some.tgz` that can result when chart archive files are…

  • CVE-2021-32690MedJun 16, 2021
    risk 0.37cvss 6.8epss 0.01

    Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that…

  • CVE-2025-55199MedAug 14, 2025
    risk 0.35cvss 6.5epss 0.00

    Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been resolved in Helm 3.18.5. A…

  • CVE-2025-55198MedAug 14, 2025
    risk 0.35cvss 6.5epss 0.00

    Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring YAML files are…

  • CVE-2025-32387MedApr 9, 2025
    risk 0.35cvss 6.5epss 0.00

    Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. This issue has been resolved in Helm…

  • CVE-2025-32386MedApr 9, 2025
    risk 0.35cvss 6.5epss 0.00

    Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to…

  • CVE-2024-25620MedFeb 15, 2024
    risk 0.35cvss 6.4epss 0.01

    Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file includes a relative path change, the chart would be saved outside its expected…

  • CVE-2022-22520MedSep 14, 2022
    risk 0.35cvss 5.3epss 0.01

    A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.

  • CVE-2022-36055MedSep 1, 2022
    risk 0.35cvss 6.5epss 0.01

    Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided by the CNCF, identified input to functions in the _strvals_ package that can cause an out of memory panic. The _strvals_ package contains a parser that turns…

  • CVE-2020-35570MedFeb 16, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.

  • CVE-2020-35566MedFeb 16, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion.

  • CVE-2020-35561MedFeb 16, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.

  • CVE-2023-34412MedAug 17, 2023
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS).

  • CVE-2021-21303MedFeb 5, 2021
    risk 0.31cvss 5.9epss 0.01

    Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. In Helm from version 3.0 and before version 3.5.2, there a few cases where data loaded from…

  • CVE-2023-4834MedOct 16, 2023
    risk 0.28cvss 4.3epss 0.00

    In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in…

  • CVE-2023-1779MedJun 6, 2023
    risk 0.28cvss 4.3epss 0.01

    Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges to view a limited amount of another…

  • CVE-2022-23526MedDec 15, 2022
    risk 0.28cvss 5.3epss 0.01

    Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that can cause a segmentation violation. The _chartutil_ package contains a parser that loads a JSON Schema…

  • CVE-2022-23525MedDec 15, 2022
    risk 0.28cvss 5.3epss 0.01

    Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the _repo_package. The _repo_ package contains a handler that processes the index file of a repository. For example, the Helm client adds…

  • CVE-2022-23524MedDec 15, 2022
    risk 0.28cvss 5.3epss 0.01

    Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow…

  • CVE-2021-34574MedAug 2, 2021
    risk 0.28cvss 4.3epss 0.01

    In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request…

  • CVE-2020-35568MedFeb 16, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response allows an authenticated attacker to gain non-public information about other users…

  • CVE-2026-35206MedApr 9, 2026
    risk 0.22cvss 4.4epss 0.00

    Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working…

  • CVE-2023-25165MedFeb 8, 2023
    risk 0.21cvss 4.3epss 0.01

    Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a…

  • CVE-2020-15184LowSep 17, 2020
    risk 0.17cvss 3.7epss 0.01

    In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is…

  • CVE-2020-4053LowJun 16, 2020
    risk 0.17cvss 3.7epss 0.01

    In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plugins from a tar archive over HTTP. It is possible for a malicious plugin author to inject a relative path into a plugin archive, and copy a file outside of the…

  • CVE-2020-15186LowSep 17, 2020
    risk 0.15cvss 3.4epss 0.01

    In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly. As a result, a malicious plugin author could use characters in a plugin name that would result in unexpected behavior, such as duplicating the name of another plugin or spoofing the output to…

  • CVE-2020-15187LowSep 17, 2020
    risk 0.13cvss 3.0epss 0.02

    In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one always used. If a plugin is compromised, this lowers the level of access that an attacker needs to modify a plugin's install hooks, causing a local execution…

  • CVE-2020-15185LowSep 17, 2020
    risk 0.07cvss 2.2epss 0.01

    In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this…

  • CVE-2006-1407Mar 28, 2006
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.

Page 1 of 2