VYPR

Vendor CVEs

Linux Foundation

All CVEs

558 total · sorted by risk
  • CVE-2026-39984MedApr 15, 2026
    risk 0.29cvss 5.5epss 0.00

    Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the…

  • CVE-2026-34447MedApr 1, 2026
    risk 0.29cvss 5.5epss 0.00

    Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows reading files outside the model directory. This issue has been patched in version…

  • CVE-2026-31890MedMar 12, 2026
    risk 0.29cvss 5.5epss 0.00

    Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior to 0.50.1, in a situation where the ring-buffer of a gadget is – incidentally or maliciously – already full, the gadget will…

  • CVE-2025-64329MedNov 7, 2025
    risk 0.29cvss 5.5epss 0.00

    containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine…

  • CVE-2024-20152MedJan 6, 2025
    risk 0.29cvss 4.4epss 0.00

    In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 /…

  • CVE-2024-20085MedSep 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944204; Issue ID: MSV-1560.

  • CVE-2024-20084MedSep 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944210; Issue ID: MSV-1561.

  • CVE-2024-20052MedApr 1, 2024
    risk 0.29cvss 4.4epss 0.00

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541761.

  • CVE-2024-20050MedApr 1, 2024
    risk 0.29cvss 4.4epss 0.00

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757.

  • CVE-2024-20049MedApr 1, 2024
    risk 0.29cvss 4.4epss 0.00

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID: ALPS08541765.

  • CVE-2023-32815MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08037801; Issue ID: ALPS08037801.

  • CVE-2023-32813MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017370; Issue ID: ALPS08017370.

  • CVE-2023-32810MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Issue ID: ALPS07867212.

  • CVE-2023-32807MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588360; Issue ID: ALPS07588360.

  • CVE-2023-20796MedAug 7, 2023
    risk 0.29cvss 4.4epss 0.00

    In power, there is a possible memory corruption due to an incorrect bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929790; Issue ID: ALPS07929790.

  • CVE-2023-20790MedAug 7, 2023
    risk 0.29cvss 4.4epss 0.00

    In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07740194; Issue ID: ALPS07740194.

  • CVE-2023-20747MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In vcu, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALPS07519121.

  • CVE-2023-20731MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573495; Issue ID: ALPS07573495.

  • CVE-2023-20730MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573552; Issue ID: ALPS07573552.

  • CVE-2023-20729MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573552; Issue ID: ALPS07573575.

  • CVE-2023-20728MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573603; Issue ID: ALPS07573603.

  • CVE-2023-20727MedJun 6, 2023
    risk 0.29cvss 4.4epss 0.00

    In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588531; Issue ID: ALPS07588531.

  • CVE-2022-31080MedJul 11, 2022
    risk 0.29cvss 4.4epss 0.01

    KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient can cause a DoS from memory exhaustion. The entire body of…

  • CVE-2022-31079MedJul 11, 2022
    risk 0.29cvss 4.4epss 0.01

    KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the Cloud Stream server and the Edge Stream server reads the entire message into memory without imposing a…

  • CVE-2022-31078MedJul 11, 2022
    risk 0.29cvss 4.4epss 0.01

    KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the CloudCore Router does not impose a limit on the size of responses to requests made by the REST handler.…

  • CVE-2022-31074MedJul 11, 2022
    risk 0.29cvss 4.5epss 0.01

    KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, several endpoints in the Cloud AdmissionController may be susceptible to a DoS attack if an HTTP request…

  • CVE-2022-31030MedJun 9, 2022
    risk 0.29cvss 5.5epss 0.00

    containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume…

  • CVE-2021-29136MedApr 6, 2021
    risk 0.29cvss 5.5epss 0.00

    Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.

  • CVE-2026-58211MedJul 8, 2026
    risk 0.28cvss 5.4epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing…

  • CVE-2026-44374MedMay 14, 2026
    risk 0.28cvss 4.3epss 0.00

    Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity…

  • CVE-2026-40923MedApr 21, 2026
    risk 0.28cvss 5.4epss 0.00

    Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restricted…

  • CVE-2026-24003MedJan 26, 2026
    risk 0.28cvss 4.3epss 0.00

    EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification including authentication, and send requests that transition to forbidden states relative to the current one, thereby updating the current…

  • CVE-2025-68140MedJan 21, 2026
    risk 0.28cvss 4.3epss 0.00

    EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has been verified, it is checked whether the submitted session ID matches the registered one. However, if no session has been registered, the default value is 0.…

  • CVE-2025-68139MedJan 21, 2026
    risk 0.28cvss 4.3epss 0.00

    EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminate_connection_on_failed_response` is `False`, which leaves the responsibility for session and connection termination to the EV. In this configuration, any…

  • CVE-2024-22244MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Open Redirect in Harbor  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.

  • CVE-2023-33199MedMay 26, 2023
    risk 0.28cvss 5.3epss 0.01

    Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects supply chain. A malformed proposed entry of the `intoto/v0.0.2` type can cause a panic on a thread within the Rekor process. The thread is recovered so the client…

  • CVE-2019-19030MedDec 26, 2022
    risk 0.28cvss 5.3epss 0.02

    Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

  • CVE-2021-36157MedAug 3, 2021
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a…

  • CVE-2020-29662MedFeb 2, 2021
    risk 0.28cvss 5.3epss 0.01

    In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.

  • CVE-2020-13794MedSep 30, 2020
    risk 0.28cvss 4.3epss 0.01

    Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.

  • CVE-2020-13788MedJul 15, 2020
    risk 0.28cvss 4.3epss 0.01

    Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

  • CVE-2019-3990MedDec 3, 2019
    risk 0.28cvss 4.3epss 0.01

    A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the…

  • CVE-2026-54712MedJul 1, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, the RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the…

  • CVE-2026-33015MedMar 26, 2026
    risk 0.27cvss 5.2epss 0.00

    EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop (StopTransaction), the EVSE can return to `PrepareCharging` via the EV's BCB toggle, allowing session restart. This breaks the irreversibility of remote stop…

  • CVE-2026-33014MedMar 26, 2026
    risk 0.27cvss 5.2epss 0.00

    EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorization response restores `authorized` back to true, defeating the `stop_transaction()` call condition on PowerOff events. As a result, the transaction can remain…

  • CVE-2026-27813MedMar 26, 2026
    risk 0.27cvss 5.3epss 0.00

    EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This is triggered by EV plug-in/unplug and RFID/RemoteStart/OCPP authorization events (or delayed authorization response). Version 2026.2.0 contains a patch.

  • CVE-2026-33219MedMar 25, 2026
    risk 0.27cvss 5.3epss 0.01

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this…

  • CVE-2026-4538MedMar 22, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might…

  • CVE-2026-25152MedJan 30, 2026
    risk 0.27cvss 5.3epss 0.00

    Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, a path traversal vulnerability in the TechDocs…

  • CVE-2026-24117MedJan 22, 2026
    risk 0.27cvss 5.3epss 0.00

    Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the…

Page 9 of 12