VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2023-32192High· 8.3
2y ago

Rancher API Server Cross-site Scripting Vulnerability

Rancher API Server Cross-site Scripting Vulnerability

▾ Twilightrancher · github.com/rancher/apiserverEPSS 0.37%via OSV
CVE-2024-23448Medium· 5.7
2y ago

APM Server vulnerable to Insertion of Sensitive Information into Log File

APM Server vulnerable to Insertion of Sensitive Information into Log File

▾ Sunlitelastic · github.com/elastic/apm-serverEPSS 0.67%via OSV
GHSA-5x4g-q5rc-36jpLow
2y ago

Etcd pkg Insecure ciphers are allowed by default

Etcd pkg Insecure ciphers are allowed by default

▾ Sunlitetcd · go.etcd.io/etcd/client/pkg/v3via OSV
CVE-2021-43798High· 7.5CISA KEVPoC
2y ago

Grafana path traversal

Grafana path traversal

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 89%via OSV
CVE-2020-27534Medium· 5.3
2y ago

Path Traversal in Moby builder

Path Traversal in Moby builder

▾ Sunlitmoby · github.com/moby/mobyEPSS 1.8%via OSV
CVE-2024-23652Critical· 10.0PoC
2y ago

BuildKit vulnerable to possible host system access from mount stub cleaner

BuildKit vulnerable to possible host system access from mount stub cleaner

▾ Abyssalmoby · github.com/moby/buildkitEPSS 2.1%via OSV
CVE-2019-19499Medium· 6.5
2y ago

Grafana Arbitrary File Read

Grafana Arbitrary File Read

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 3.6%via OSV
CVE-2020-15114High· 7.7
2y ago

Etcd Gateway can include itself as an endpoint resulting in resource exhaustion

Etcd Gateway can include itself as an endpoint resulting in resource exhaustion

▾ Twilightetcd · go.etcd.io/etcdEPSS 1.2%via OSV
CVE-2021-21284Medium· 6.8
2y ago

moby Access to remapped root allows privilege escalation to real root

moby Access to remapped root allows privilege escalation to real root

▾ Sunlitmoby · github.com/moby/mobyEPSS 1.1%via OSV
CVE-2021-21334Medium· 6.3
2y ago

containerd environment variable leak

containerd environment variable leak

▾ Sunlitcontainerd · github.com/containerd/containerdEPSS 2.0%via OSV
CVE-2021-21285Medium· 6.5
2y ago

moby docker daemon crash during image pull of malicious image

moby docker daemon crash during image pull of malicious image

▾ Sunlitmoby · github.com/moby/mobyEPSS 3.3%via OSV
CVE-2021-41091Medium· 5.9PoC
2y ago

Moby (Docker Engine) Insufficiently restricted permissions on data directory

Moby (Docker Engine) Insufficiently restricted permissions on data directory

▾ Twilightmoby · github.com/moby/mobyEPSS 2.8%via OSV
CVE-2024-23332Medium· 4.0
2y ago

Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from co…

Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry

▾ Sunlitnotaryproject · github.com/notaryproject/notationEPSS 0.29%via OSV
CVE-2024-22424High· 8.3
2y ago

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

▾ Twilightargoproj · github.com/argoproj/argo-cdEPSS 0.39%via OSV
CVE-2024-22199Critical· 9.3
2y ago

Django Template Engine Vulnerable to XSS

Django Template Engine Vulnerable to XSS

▾ Midnightgofiber · github.com/gofiber/template/django/v3EPSS 0.48%via OSV
CVE-2023-49569Critical· 9.8
2y ago

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

▾ Midnightgo-git · github.com/go-git/go-git/v5EPSS 1.5%via OSV
CVE-2023-30617Medium· 6.5
2y ago

Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster

Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster

▾ Sunlitopenkruise · github.com/openkruise/kruiseEPSS 0.49%via OSV
CVE-2023-46739Medium· 6.5
2y ago

CubeFS timing attack can leak user passwords

CubeFS timing attack can leak user passwords

▾ Sunlitcubefs · github.com/cubefs/cubefsEPSS 0.35%via OSV
CVE-2023-46740Medium· 6.5
2y ago

Insecure random string generator used for sensitive data

Insecure random string generator used for sensitive data

▾ Sunlitcubefs · github.com/cubefs/cubefsEPSS 0.44%via OSV
CVE-2023-49568High· 7.5
2y ago

Maliciously crafted Git server replies can cause DoS on go-git clients

Maliciously crafted Git server replies can cause DoS on go-git clients

▾ Twilightgo-git · github.com/go-git/go-git/v5EPSS 0.70%via OSV
GHSA-7ww5-4wqc-m92cMedium
2y ago

containerd allows RAPL to be accessible to a container

containerd allows RAPL to be accessible to a container

▾ Sunlitcontainerd · github.com/containerd/containerdvia OSV
CVE-2023-50422Critical· 9.1
2y ago

Improper Privilege Management in github.com/sap/cloud-security-client-go

Improper Privilege Management in github.com/sap/cloud-security-client-go

▾ Midnightsap · github.com/sap/cloud-security-client-goEPSS 1.4%via OSV
CVE-2023-6458High· 7.1
2y ago

Mattermost Injection vulnerability

Mattermost Injection vulnerability

▾ Twilightmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.64%via OSV
CVE-2023-6459Medium· 5.3
2y ago

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.53%via OSV
CVE-2023-49290Medium· 5.3
2y ago

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

▾ Sunlitlestrrat-go · github.com/lestrrat-go/jwxEPSS 0.73%via OSV
CVE-2023-47106Medium· 6.5
2y ago

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.63%via OSV
CVE-2023-47124Medium· 5.9
2y ago

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.79%via OSV
CVE-2023-47633High· 7.5
2y ago

Traefik docker container using 100% CPU

Traefik docker container using 100% CPU

▾ Twilighttraefik · github.com/traefik/traefik/v2EPSS 1.3%via OSV
CVE-2023-49097High· 8.1
2y ago

ZITADEL Account Takeover via Malicious Host Header Injection

ZITADEL Account Takeover via Malicious Host Header Injection

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.77%via OSV
CVE-2023-6202Medium· 4.3
2y ago

Mattermost Improper Access Control vulnerability

Mattermost Improper Access Control vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.44%via OSV
CVEs tagged “go” — page 48 · VulnSea