VYPR

Vendor CVEs

Linux Foundation

All CVEs

564 total · sorted by risk
  • CVE-2022-31006HigSep 9, 2022
    risk 0.42cvss 7.5epss 0.01

    indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-node, an attacker can max out the number of client connections allowed by the ledger, leaving the ledger unable to be used for its…

  • CVE-2022-24778HigMar 25, 2022
    risk 0.42cvss 7.5epss 0.03

    The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images. The imgcrypt function `CheckAuthorization` is supposed to check whether…

  • CVE-2022-24777HigMar 25, 2022
    risk 0.42cvss 7.5epss 0.01

    grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect logic when handling GOAWAY frames. The…

  • CVE-2021-45702HigDec 27, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-free.

  • CVE-2021-41131HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.01

    python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path traversal vulnerability that in the worst case can overwrite files ending in `.json` anywhere on the client system on a call to…

  • CVE-2021-3127HigMar 16, 2021
    risk 0.42cvss 7.5epss 0.01

    NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.

  • CVE-2021-21369MedMar 9, 2021
    risk 0.42cvss 6.5epss 0.02

    Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vulnerability involving the HTTP JSON-RPC API service. If username and password authentication is enabled for the HTTP JSON-RPC API…

  • CVE-2020-11093HigDec 24, 2020
    risk 0.42cvss 7.5epss 0.01

    Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperledger Indy before version 1.12.4, there is lack of signature verification on a specific transaction which enables an attacker to make certain unauthorized…

  • CVE-2020-26521HigNov 6, 2020
    risk 0.42cvss 7.5epss 0.02

    The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).

  • CVE-2020-26149HigSep 30, 2020
    risk 0.42cvss 7.5epss 0.01

    NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.

  • CVE-2020-1759MedApr 13, 2020
    risk 0.42cvss 6.4epss 0.02

    A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data…

  • CVE-2019-16919HigOct 18, 2019
    risk 0.42cvss 7.5epss 0.02

    Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not…

  • CVE-2019-16884HigSep 25, 2019
    risk 0.42cvss 7.5epss 0.04

    runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

  • CVE-2019-13126HigJul 29, 2019
    risk 0.42cvss 7.5epss 0.02

    An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authenticated.

  • CVE-2026-33247HigMar 25, 2026
    risk 0.41cvss 7.4epss 0.01

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any…

  • CVE-2025-66623HigDec 5, 2025
    risk 0.41cvss 7.4epss 0.00

    Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.1, in some situations, Strimzi creates an incorrect Kubernetes Role which grants the Apache Kafka Connect and Apache Kafka…

  • CVE-2025-5150MedMay 25, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /docarray/data/torch_dataset.py of the component Web API. The manipulation leads to improperly controlled modification of object…

  • CVE-2024-20055MedApr 1, 2024
    risk 0.41cvss 6.3epss 0.00

    In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.

  • CVE-2024-25621HigNov 6, 2025
    risk 0.40cvss 7.3epss 0.00

    containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`,…

  • CVE-2024-20107MedNov 4, 2024
    risk 0.40cvss 6.2epss 0.00

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823.

  • CVE-2021-20288HigApr 15, 2021
    risk 0.40cvss 7.2epss 0.02

    An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a…

  • CVE-2019-19029HigMar 20, 2020
    risk 0.40cvss 7.2epss 0.02

    Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.

  • CVE-2018-20731MedJan 17, 2019
    risk 0.40cvss 6.1epss 0.01

    A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via User-Chat.php.

  • CVE-2018-20729MedJan 17, 2019
    risk 0.40cvss 6.1epss 0.01

    A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via the reg parameter in mh.php.

  • CVE-2026-58213HigJul 8, 2026
    risk 0.39cvss 7.1epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode…

  • CVE-2026-35167HigApr 6, 2026
    risk 0.39cvss 7.1epss 0.00

    Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.py constructs filesystem paths by directly interpolating user-supplied version strings without sanitization. Because version strings are used as path…

  • CVE-2026-26074HigMar 26, 2026
    risk 0.39cvss 7.0epss 0.00

    EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::map<std::queue>` corruption. The trigger is CSMS GetLog/UpdateFirmware request (network) with an EVSE fault event (physical). This results in TSAN reports concurrent…

  • CVE-2026-33217HigMar 25, 2026
    risk 0.39cvss 7.1epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT…

  • CVE-2023-27561HigMar 3, 2023
    risk 0.39cvss 7.0epss 0.00

    runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this…

  • CVE-2020-10750HigJun 19, 2020
    risk 0.39cvss 7.1epss 0.00

    Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. This flaw allows an attacker with access to the container's log file to discover the Kafka credentials.

  • CVE-2020-10749MedJun 3, 2020
    risk 0.39cvss 6.0epss 0.02

    A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router…

  • CVE-2019-19921HigFeb 12, 2020
    risk 0.39cvss 7.0epss 0.00

    runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This…

  • CVE-2026-27133MedFeb 20, 2026
    risk 0.38cvss 5.9epss 0.00

    Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 to before 0.50.1, when a chain consisting of multiple CA (Certificate Authority) certificates is used in the trusted certificates configuration of a…

  • CVE-2020-1760MedApr 23, 2020
    risk 0.38cvss 5.8epss 0.02

    A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

  • CVE-2026-58208MedJul 8, 2026
    risk 0.37cvss 6.8epss 0.01

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an…

  • CVE-2026-44247MedMay 27, 2026
    risk 0.37cvss 6.8epss 0.00

    Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluster pod that can reach the webhook endpoint may send an arbitrarily large request…

  • CVE-2023-37918MedJul 21, 2023
    risk 0.37cvss 6.8epss 0.01

    Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability has been found in Dapr that allows bypassing API token authentication, which is used by the Dapr sidecar to authenticate calls coming from the application, with…

  • CVE-2023-25571MedFeb 14, 2023
    risk 0.37cvss 6.8epss 0.00

    Backstage is an open platform for building developer portals. `@backstage/catalog-model` prior to version 1.2.0, `@backstage/core-components` prior to 0.12.4, and `@backstage/plugin-catalog-backend` prior to 1.7.2 are affected by a cross-site scripting vulnerability. This…

  • CVE-2021-41151MedOct 18, 2021
    risk 0.37cvss 6.8epss 0.01

    Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitive files from the environment where Scaffolder Tasks are run. The attack is executed by crafting a custom Scaffolder template with a…

  • CVE-2021-32661MedJun 3, 2021
    risk 0.37cvss 6.8epss 0.01

    Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.5, a malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within…

  • CVE-2021-32660MedJun 3, 2021
    risk 0.37cvss 6.8epss 0.01

    Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal actor is able to upload documentation content with…

  • CVE-2019-16097MedSep 8, 2019
    risk 0.37cvss 6.5epss 0.22

    core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without…

  • CVE-2025-67499MedDec 10, 2025
    risk 0.36cvss 6.6epss 0.00

    The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versions 1.6.0 through 1.8.0 inadvertently forward all traffic with the same destination port as the host port when the portmap plugin is configured with the…

  • CVE-2023-52728MedApr 30, 2024
    risk 0.36cvss 5.5epss 0.00

    Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString.

  • CVE-2021-31232MedApr 30, 2021
    risk 0.36cvss 5.5epss 0.00

    The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be…

  • CVE-2011-2924MedNov 19, 2019
    risk 0.36cvss 5.5epss 0.00

    foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…

  • CVE-2011-2923MedNov 19, 2019
    risk 0.36cvss 5.5epss 0.00

    foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…

  • CVE-2026-58254MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not consistently to messages arriving through leafnode connections,…

  • CVE-2026-58252MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could receive messages on denied subjects when a wildcard subscription overlapped with a configured wildcard deny rule…

  • CVE-2026-58251MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription, because…

Page 7 of 12