VulnSea

github.com/argoproj/argo-cd vulnerabilities

CVEs whose affected-version data names the github.com/argoproj/argo-cd package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

CVE-2025-47933Critical· 9.0
1y ago

Argo CD allows cross-site scripting on repositories page

Argo CD allows cross-site scripting on repositories page

Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.46%via OSV
CVE-2025-23216Medium· 6.8
1y ago

Argo CD does not scrub secret values from patch errors

Argo CD does not scrub secret values from patch errors

Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.47%via OSV
CVE-2024-36106Medium· 4.3
2y ago

Argo-cd authenticated users can enumerate clusters by name

Argo-cd authenticated users can enumerate clusters by name

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.41%via OSV
CVE-2024-21661High· 7.5
2y ago

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

Twilightargoproj · github.com/argoproj/argo-cdEPSS 1.2%via OSV
CVE-2024-28175Critical· 9.0
2y ago

Cross-site scripting on application summary component

Cross-site scripting on application summary component

Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.65%via OSV
CVE-2023-50726Medium· 6.4
2y ago

Users with `create` but not `override` privileges can perform local sync

Users with `create` but not `override` privileges can perform local sync

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.53%via OSV
CVE-2024-22424High· 8.3
2y ago

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

Twilightargoproj · github.com/argoproj/argo-cdEPSS 0.39%via OSV
CVE-2023-40026Medium· 5.0
2y ago

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.50%via OSV
CVE-2022-41354Medium· 5.3
3y ago

Argo CD authenticated but unauthorized users may enumerate Application names via the API

Argo CD authenticated but unauthorized users may enumerate Application names via the API

Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.64%via OSV
CVE-2023-23947Critical· 9.1
3y ago

Users with any cluster secret update access may update out-of-bounds cluster secrets

Users with any cluster secret update access may update out-of-bounds cluster secrets

Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.67%via OSV
CVE-2022-1025Critical· 9.9
4y ago

Improper access control allows admin privilege escalation in Argo CD

Improper access control allows admin privilege escalation in Argo CD

Midnightargoproj · github.com/argoproj/argo-cdEPSS 1.3%via OSV
CVE-2022-24348High· 7.7PoC
4y ago

Path traversal and dereference of symlinks in Argo CD

Path traversal and dereference of symlinks in Argo CD

Midnightargoproj · github.com/argoproj/argo-cd/v2EPSS 2.7%via OSV
github.com/argoproj/argo-cd vulnerabilities (CVEs) · VulnSea