VYPR

Vendor CVEs

Linux Foundation

All CVEs

558 total · sorted by risk
  • CVE-2022-31073MedJul 11, 2022
    risk 0.35cvss 6.5epss 0.02

    KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the ServiceBus server on the edge side may be susceptible to a DoS attack if an HTTP request containing a…

  • CVE-2022-26652MedMar 10, 2022
    risk 0.35cvss 6.5epss 0.02

    NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.

  • CVE-2021-39228MedSep 17, 2021
    risk 0.35cvss 6.5epss 0.01

    Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. This vulnerability is a memory safety Issue when using `patch` or `merge` on `state` and assign the result back to `state`. In this case, affected versions of…

  • CVE-2021-32662MedJun 3, 2021
    risk 0.35cvss 6.5epss 0.01

    Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor could read sensitive files from the environment where TechDocs…

  • CVE-2020-10753MedJun 26, 2020
    risk 0.35cvss 5.4epss 0.02

    A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the…

  • CVE-2020-6173MedJan 14, 2020
    risk 0.35cvss 5.3epss 0.02

    TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.

  • CVE-2015-1857MedApr 27, 2018
    risk 0.35cvss 5.3epss 0.02

    The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.

  • CVE-2025-55554MedSep 25, 2025
    risk 0.34cvss 5.3epss 0.00

    pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

  • CVE-2025-46153MedSep 25, 2025
    risk 0.34cvss 5.3epss 0.00

    PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.

  • CVE-2025-46152MedSep 25, 2025
    risk 0.34cvss 5.3epss 0.00

    In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.

  • CVE-2025-46150MedSep 25, 2025
    risk 0.34cvss 5.3epss 0.00

    In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.

  • CVE-2025-46149MedSep 25, 2025
    risk 0.34cvss 5.3epss 0.00

    In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.

  • CVE-2025-46148MedSep 25, 2025
    risk 0.34cvss 5.3epss 0.00

    In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.

  • CVE-2025-59354MedSep 17, 2025
    risk 0.34cvss 5.3epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for downloaded files. This allows attackers to replace files with malicious ones that have a colliding…

  • CVE-2025-59351MedSep 17, 2025
    risk 0.34cvss 5.3epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function returns an error. This can result in a nil dereference, and cause code to panic. This vulnerability…

  • CVE-2025-59350MedSep 17, 2025
    risk 0.34cvss 5.3epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access control mechanism for the Proxy feature uses simple string comparisons and is therefore vulnerable to timing attacks. An attacker may try to guess the password one…

  • CVE-2025-59346MedSep 17, 2025
    risk 0.34cvss 5.3epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery (SSRF) vulnerability that enables users to force DragonFly2’s components to make requests to internal services that are…

  • CVE-2024-20147MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.00

    In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389046 (Note: For MT79XX…

  • CVE-2024-9802MedOct 10, 2024
    risk 0.34cvss 5.3epss 0.00

    The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to…

  • CVE-2023-32871MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.

  • CVE-2024-34043MedApr 30, 2024
    risk 0.34cvss 5.3epss 0.00

    O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message.

  • CVE-2021-4314MedJan 18, 2023
    risk 0.34cvss 5.3epss 0.00

    It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What…

  • CVE-2021-21334MedMar 10, 2021
    risk 0.34cvss 6.3epss 0.02

    In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may…

  • CVE-2025-2148MedMar 10, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption.…

  • CVE-2023-28642MedMar 29, 2023
    risk 0.33cvss 6.1epss 0.00

    runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by…

  • CVE-2023-25153MedFeb 16, 2023
    risk 0.33cvss 6.2epss 0.00

    containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of…

  • CVE-2020-15157MedOct 16, 2020
    risk 0.33cvss 6.1epss 0.02

    In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise…

  • CVE-2019-10785MedFeb 13, 2020
    risk 0.33cvss 6.1epss 0.02

    dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.

  • CVE-2023-30841MedApr 26, 2023
    risk 0.32cvss 6.0epss 0.00

    Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as ConfigMaps instead of Secrets. This…

  • CVE-2022-31075MedJul 11, 2022
    risk 0.32cvss 4.9epss 0.01

    KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, EdgeCore may be susceptible to a DoS attack on CloudHub if an attacker was to send a well-crafted HTTP…

  • CVE-2021-43784MedDec 6, 2021
    risk 0.32cvss 6.0epss 0.02

    runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serialization system for specifying the relevant container configuration to the `C` portion of the code (responsible for the based…

  • CVE-2019-1010252MedJul 18, 2019
    risk 0.32cvss 4.9epss 0.01

    The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in FlowRuleManager.java.…

  • CVE-2019-1010250MedJul 18, 2019
    risk 0.32cvss 4.9epss 0.01

    The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java…

  • CVE-2019-1010249MedJul 18, 2019
    risk 0.32cvss 4.9epss 0.01

    The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java…

  • CVE-2026-49835MedJul 17, 2026
    risk 0.31cvss 5.9epss 0.00

    Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before…

  • CVE-2026-26073MedMar 26, 2026
    risk 0.31cvss 5.9epss 0.00

    EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/`std::deque` corruption. The trigger is powermeter public key update and EV session/error events (while OCPP not started). This results in a TSAN data race…

  • CVE-2026-32235MedMar 12, 2026
    risk 0.31cvss 5.9epss 0.00

    Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID…

  • CVE-2026-27571MedFeb 24, 2026
    risk 0.31cvss 5.9epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation bound the…

  • CVE-2025-68138MedJan 21, 2026
    risk 0.31cvss 4.7epss 0.00

    EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol. In libocpp prior to version 0.30.1, pointers returned by the `strdup` calls are never freed. At each connection attempt, the newly allocated memory area will…

  • CVE-2026-22772MedJan 12, 2026
    risk 0.31cvss 5.8epss 0.00

    Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal…

  • CVE-2025-20765MedDec 2, 2025
    risk 0.31cvss 4.7epss 0.00

    In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10190802; Issue ID: MSV-4833.

  • CVE-2025-47290MedMay 20, 2025
    risk 0.31cvss 5.9epss 0.00

    containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify the host file system. The only affected version of…

  • CVE-2023-20902MedNov 9, 2023
    risk 0.31cvss 5.9epss 0.00

    A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information.

  • CVE-2023-30840MedMay 8, 2023
    risk 0.31cvss 5.8epss 0.00

    Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applications. Starting in version 0.7.0 and prior to version 0.8.6, if a malicious user gains control of a Kubernetes node running fluid csi pod (controlled by the…

  • CVE-2022-29162MedMay 17, 2022
    risk 0.31cvss 5.9epss 0.00

    runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux…

  • CVE-2022-24769MedMar 24, 2022
    risk 0.31cvss 5.9epss 0.00

    Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an…

  • CVE-2026-20435MedMar 2, 2026
    risk 0.30cvss 4.6epss 0.00

    In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-6944MedJan 4, 2024
    risk 0.30cvss 5.7epss 0.01

    A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw…

  • CVE-2022-23471MedDec 7, 2022
    risk 0.30cvss 5.7epss 0.01

    containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize events if a TTY is requested. If the user's process fails…

  • CVE-2026-47262MedJul 1, 2026
    risk 0.29cvss 5.5epss 0.00

    containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion…

Page 8 of 12