VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

CVE-2021-41092Medium· 5.4
2y ago

Docker CLI leaks private registry credentials to registry-1.docker.io

Docker CLI leaks private registry credentials to registry-1.docker.io

▾ Sunlitdocker · github.com/docker/cliEPSS 1.7%via OSV
CVE-2024-37152Medium· 5.3PoC
2y ago

Unauthenticated Access to sensitive settings in Argo CD

Unauthenticated Access to sensitive settings in Argo CD

▾ Twilightargoproj · github.com/argoproj/argo-cd/v2/serverEPSS 2.3%via OSV
CVE-2024-36106Medium· 4.3
2y ago

Argo-cd authenticated users can enumerate clusters by name

Argo-cd authenticated users can enumerate clusters by name

▾ Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.41%via OSV
GO-2024-2880None
2y ago

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

▾ Sunlittraefik · github.com/traefik/traefikvia OSV
GO-2024-2726None
2y ago

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

▾ Sunlittraefik · github.com/traefik/traefikvia OSV
CVE-2024-5154High· 8.1
2y ago

malicious container creates symlink "mtab" on the host External

malicious container creates symlink "mtab" on the host External

▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.2%via OSV
CVE-2024-22261Low· 2.7
2y ago

SQL Injection in Harbor scan log API

SQL Injection in Harbor scan log API

▾ Sunlitgoharbor · github.com/goharbor/harborEPSS 0.42%via OSV
CVE-2024-22244Medium· 4.3
2y ago

Open Redirect URL in Harbor

Open Redirect URL in Harbor

▾ Sunlitgoharbor · github.com/goharbor/harborEPSS 0.36%via OSV
CVE-2024-35232Low· 3.7
2y ago

github.com/huandu/facebook may expose access_token in error message.

github.com/huandu/facebook may expose access_token in error message.

▾ Sunlithuandu · github.com/huandu/facebook/v2EPSS 0.50%via OSV
GHSA-f7cq-5v43-8pwpMedium· 5.3
2y ago

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop

▾ Sunlittraefik · github.com/traefik/traefik/v2via OSV
CVE-2024-35223Medium· 5.3
2y ago

Dapr API Token Exposure

Dapr API Token Exposure

▾ Sunlitdapr · github.com/dapr/daprEPSS 0.44%via OSV
CVE-2024-35175Medium· 5.3
2y ago

sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address

sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address

▾ Sunlittg123 · github.com/tg123/sshpiperEPSS 0.26%via OSV
CVE-2021-41244Critical· 9.1
2y ago

Grafana Fine-grained access control vulnerability

Grafana Fine-grained access control vulnerability

▾ Midnightgrafana · github.com/grafana/grafanaEPSS 2.9%via OSV
CVE-2021-43815Medium· 4.3
2y ago

Grafana directory traversal for .cvs files

Grafana directory traversal for .cvs files

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.7%via OSV
CVE-2024-3727High· 8.3
2y ago

A flaw was found in the github.com/containers/image library

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

▾ Twilightcontainers · github.com/containers/imageEPSS 1.3%via NVD
CVE-2024-34079Low· 3.7
2y ago

octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage

octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage

▾ Sunlitocto-sts · github.com/octo-sts/appEPSS 0.58%via OSV
CVE-2024-32886Medium· 4.9
2y ago

Vitess vulnerable to infinite memory consumption and vtgate crash

Vitess vulnerable to infinite memory consumption and vtgate crash

▾ Sunlitvitessio · github.com/vitessio/vitessEPSS 0.75%via OSV
CVE-2024-33394Medium· 5.9
2y ago

kubevirt allows a local attacker to execute arbitrary code via a crafted command

kubevirt allows a local attacker to execute arbitrary code via a crafted command

▾ Sunlitkubevirt · kubevirt.io/kubevirtEPSS 0.33%via OSV
CVE-2024-32963Medium· 4.2
2y ago

Navidrome Parameter Tampering vulnerability

Navidrome Parameter Tampering vulnerability

▾ Sunlitnavidrome · github.com/navidrome/navidromeEPSS 0.41%via OSV
CVE-2024-33522Medium· 6.7
2y ago

Calico privilege escalation vulnerability

Calico privilege escalation vulnerability

▾ Sunlitprojectcalico · github.com/projectcalico/calicoEPSS 0.22%via OSV
CVE-2023-46565High· 7.5
2y ago

Buffer Overflow vulnerability in osrg gobgp

Buffer Overflow vulnerability in osrg gobgp

▾ Twilightosrg · github.com/osrg/gobgp/v3EPSS 0.74%via OSV
CVE-2024-3154High· 7.2
2y ago

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.4%via NVD
CVE-2024-32476Medium· 6.5
2y ago

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 1.0%via OSV
CVE-2020-8559Medium· 6.8PoC
2y ago

Privilege Escalation in Kubernetes

Privilege Escalation in Kubernetes

▾ Twilightapimachinery · k8s.io/apimachineryEPSS 6.1%via OSV
CVE-2021-36775High· 8.0
2y ago

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.97%via OSV
CVE-2021-31999High· 8.8
2y ago

Rancher Privilege escalation vulnerability via malicious "Connection" header

Rancher Privilege escalation vulnerability via malicious "Connection" header

▾ Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2021-25318High· 8.8
2y ago

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

▾ Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2022-24769Medium· 5.9
2y ago

Moby (Docker Engine) started with non-empty inheritable Linux process capabilities

Moby (Docker Engine) started with non-empty inheritable Linux process capabilities

▾ Sunlitmoby · github.com/moby/mobyEPSS 0.49%via OSV
CVE-2024-30257Medium· 5.9
2y ago

1Panel's password verification is suspected to have a timing attack vulnerability

1Panel's password verification is suspected to have a timing attack vulnerability

▾ Sunlit1Panel-dev · github.com/1Panel-dev/1PanelEPSS 0.38%via OSV
GHSA-7f4j-64p6-5h5vMedium
2y ago

Traefik affected by HTTP/2 CONTINUATION flood in net/http

Traefik affected by HTTP/2 CONTINUATION flood in net/http

▾ Sunlittraefik · github.com/traefik/traefik/v2via OSV
CVEs tagged “go” — page 46 · VulnSea