VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2025-54379High· 9.8
1y ago

eKuiper API endpoints handling SQL queries with user-controlled table names.

eKuiper API endpoints handling SQL queries with user-controlled table names.

▾ Twilightlf-edge · github.com/lf-edge/ekuiper/v2EPSS 0.77%via OSV
CVE-2025-22868High· 7.5
1y ago

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

▾ Twilightx · golang.org/x/oauth2EPSS 0.87%via OSV
CVE-2025-54059Medium· 4.4
1y ago

melange's world-writable permissions expose SBOM files to potential image tampering

melange's world-writable permissions expose SBOM files to potential image tampering

▾ Sunlitmelange · chainguard.dev/melangeEPSS 0.13%via OSV
CVE-2025-3415Medium· 4.3PoC
1y ago

Grafana's insecure DingDing Alert integration exposes sensitive information

Grafana's insecure DingDing Alert integration exposes sensitive information

▾ Twilightgrafana · github.com/grafana/grafanaEPSS 0.98%via OSV
CVE-2025-53893High
1y ago

File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing

File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.36%via OSV
CVE-2025-53826High
1y ago

File Browser’s insecure JWT handling can lead to session replay attacks after logout

File Browser’s insecure JWT handling can lead to session replay attacks after logout

▾ Twilightfilebrowser · github.com/filebrowser/filebrowserEPSS 0.50%via OSV
CVE-2025-7453Low· 3.7
1y ago

ZPan Uses Hard-Coded Password

ZPan Uses Hard-Coded Password

▾ Sunlitsaltbo · github.com/saltbo/zpanEPSS 0.38%via OSV
CVE-2025-53513High· 8.8
1y ago

Juju zip slip vulnerability via authenticated endpoint

Juju zip slip vulnerability via authenticated endpoint

▾ Twilightjuju · github.com/juju/jujuEPSS 0.66%via OSV
CVE-2025-53547High· 8.5PoC
1y ago

helm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)

A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…

▾ MidnightRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9EPSS 0.38%via CSAF
CVE-2025-52996Low· 3.1
1y ago

File Browser's password protection of links is bypassable

File Browser's password protection of links is bypassable

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.36%via OSV
CVE-2025-52894Medium
1y ago

OpenBao allows cancellation of root rekey and recovery rekey operations without authentication

OpenBao allows cancellation of root rekey and recovery rekey operations without authentication

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.40%via OSV
CVE-2025-52893Medium· 4.5
1y ago

OpenBao Inserts Sensitive Information into Log File when processing malformed data

OpenBao Inserts Sensitive Information into Log File when processing malformed data

▾ Sunlitopenbao · github.com/openbao/openbao/sdk/v2EPSS 0.33%via OSV
CVE-2025-6032High· 8.3
1y ago

A flaw was found in Podman

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

▾ Twilightcontainers · github.com/containers/podman/v4EPSS 0.52%via NVD
CVE-2024-44905Medium· 6.5
1y ago

go-pg SQL injection vulnerability via the component /types/append_value.go

go-pg SQL injection vulnerability via the component /types/append_value.go

▾ Sunlitgo-pg · github.com/go-pg/pg/v10EPSS 0.44%via OSV
CVE-2025-22874High· 7.5
1y ago

crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.20EPSS 0.37%via CSAF
CVE-2025-8556Low· 3.7
1y ago

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

▾ Sunlitcloudflare · github.com/cloudflare/circlEPSS 0.48%via OSV
CVE-2025-3260High· 8.3
1y ago

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

▾ Twilightgrafana · github.com/grafana/grafanaEPSS 0.56%via OSV
CVE-2025-1792Low· 3.1
1y ago

Mattermost fails to properly enforce access controls for guest users

Mattermost fails to properly enforce access controls for guest users

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.24%via OSV
CVE-2025-3611Low· 3.1
1y ago

Mattermost fails to properly enforce access control restrictions for System Manager roles

Mattermost fails to properly enforce access control restrictions for System Manager roles

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.22%via OSV
CVE-2025-47933Critical· 9.0
1y ago

Argo CD allows cross-site scripting on repositories page

Argo CD allows cross-site scripting on repositories page

▾ Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.46%via OSV
CVE-2025-4166Medium· 4.5
1y ago

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.43%via OSV
CVE-2025-46569High
1y ago

OPA server Data API HTTP path injection of Rego

OPA server Data API HTTP path injection of Rego

▾ Twilightopen-policy-agent · github.com/open-policy-agent/opa/v1/serverEPSS 0.51%via OSV
CVE-2025-46327Low· 3.3
1y ago

Go Snowflake Driver has race condition when checking access to Easy Logging configuration file

Go Snowflake Driver has race condition when checking access to Easy Logging configuration file

▾ Sunlitsnowflakedb · github.com/snowflakedb/gosnowflakeEPSS 0.14%via OSV
CVE-2025-46599Medium· 6.8
1y ago

CNCF K3s Kubernetes kubelet configuration exposes credentials

CNCF K3s Kubernetes kubelet configuration exposes credentials

▾ Sunlitk3s-io · github.com/k3s-io/k3sEPSS 0.45%via OSV
CVE-2025-35965Medium· 6.5
1y ago

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.40%via OSV
CVE-2025-41395Medium· 6.5
1y ago

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

▾ Sunlitmattermost · github.com/mattermost/mattermost-plugin-playbooksEPSS 0.49%via OSV
CVE-2025-43971High· 8.6
1y ago

GoBGP panics due to a zero value for softwareVersionLen

GoBGP panics due to a zero value for softwareVersionLen

▾ Twilightosrg · github.com/osrg/gobgp/v3EPSS 0.55%via OSV
CVE-2025-32793Medium· 4.0
1y ago

In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters

In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.14%via OSV
GHSA-3wqc-mwfx-672pHigh· 7.5
1y ago

Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability

Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability

▾ Twilighttraefik · github.com/traefik/traefik/v3via OSV
CVE-2025-27936Medium· 5.3
1y ago

Mattermost vulnerable to Observable Timing Discrepancy

Mattermost vulnerable to Observable Timing Discrepancy

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.34%via OSV
CVEs tagged “go” — page 42 · VulnSea