VulnSea

Tagged “go”

CVEs tagged go, newest first.

1749 CVEsRSS

CVE-2023-30617Medium· 6.5
2y ago

Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster

Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster

▾ Sunlitopenkruise · github.com/openkruise/kruiseEPSS 0.49%via OSV
CVE-2023-46739Medium· 6.5
2y ago

CubeFS timing attack can leak user passwords

CubeFS timing attack can leak user passwords

▾ Sunlitcubefs · github.com/cubefs/cubefsEPSS 0.35%via OSV
CVE-2023-46740Medium· 6.5
2y ago

Insecure random string generator used for sensitive data

Insecure random string generator used for sensitive data

▾ Sunlitcubefs · github.com/cubefs/cubefsEPSS 0.44%via OSV
CVE-2023-49568High· 7.5
2y ago

Maliciously crafted Git server replies can cause DoS on go-git clients

Maliciously crafted Git server replies can cause DoS on go-git clients

▾ Twilightgo-git · github.com/go-git/go-git/v5EPSS 0.70%via OSV
GHSA-7ww5-4wqc-m92cMedium
2y ago

containerd allows RAPL to be accessible to a container

containerd allows RAPL to be accessible to a container

▾ Sunlitcontainerd · github.com/containerd/containerdvia OSV
CVE-2023-50422Critical· 9.1
2y ago

Improper Privilege Management in github.com/sap/cloud-security-client-go

Improper Privilege Management in github.com/sap/cloud-security-client-go

▾ Midnightsap · github.com/sap/cloud-security-client-goEPSS 1.4%via OSV
CVE-2023-6458High· 7.1
2y ago

Mattermost Injection vulnerability

Mattermost Injection vulnerability

▾ Twilightmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.64%via OSV
CVE-2023-6459Medium· 5.3
2y ago

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.53%via OSV
CVE-2023-49290Medium· 5.3
2y ago

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

▾ Sunlitlestrrat-go · github.com/lestrrat-go/jwxEPSS 0.73%via OSV
CVE-2023-47106Medium· 6.5
2y ago

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.63%via OSV
CVE-2023-47124Medium· 5.9
2y ago

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.79%via OSV
CVE-2023-47633High· 7.5
2y ago

Traefik docker container using 100% CPU

Traefik docker container using 100% CPU

▾ Twilighttraefik · github.com/traefik/traefik/v2EPSS 1.3%via OSV
CVE-2023-49097High· 8.1
2y ago

ZITADEL Account Takeover via Malicious Host Header Injection

ZITADEL Account Takeover via Malicious Host Header Injection

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.77%via OSV
CVE-2023-6202Medium· 4.3
2y ago

Mattermost Improper Access Control vulnerability

Mattermost Improper Access Control vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.44%via OSV
CVE-2023-47168Medium· 4.3
2y ago

Mattermost Open Redirect vulnerability

Mattermost Open Redirect vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.40%via OSV
CVE-2023-48369Medium· 5.3
2y ago

Mattermost Uncontrolled Resource Consumption vulnerability

Mattermost Uncontrolled Resource Consumption vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.63%via OSV
GHSA-2c7c-3mj9-8fqhMedium
2y ago

Decryption of malicious PBES2 JWE objects can consume unbounded system resources

Decryption of malicious PBES2 JWE objects can consume unbounded system resources

▾ Sunlitgo-jose · github.com/go-jose/go-jose/v3via OSV
CVE-2023-46402High· 7.5
2y ago

Inefficient Regular Expression Complexity in git-urls

Inefficient Regular Expression Complexity in git-urls

▾ Twilightwhilp · github.com/whilp/git-urlsEPSS 0.85%via OSV
CVE-2023-47630High· 7.1⚠ Exploited0day
2y ago

Attacker can cause Kyverno user to unintentionally consume insecure image

Attacker can cause Kyverno user to unintentionally consume insecure image

▾ Abyssalkyverno · github.com/kyverno/kyvernoEPSS 0.26%via OSV
CVE-2023-5954High· 7.5
2y ago

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.72%via OSV
CVE-2023-47111High· 7.3
2y ago

ZITADEL race condition in lockout policy execution

ZITADEL race condition in lockout policy execution

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.52%via OSV
CVE-2023-46254Medium· 4.3
2y ago

capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name

capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name

▾ Sunlitprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.41%via OSV
CVE-2023-41378High· 7.5
2y ago

Calico Typha denial of service vulnerability

Calico Typha denial of service vulnerability

▾ Twilightprojectcalico · github.com/projectcalico/calicoEPSS 0.72%via OSV
CVE-2023-3676High· 8.8
2y ago

Kubernetes privilege escalation vulnerability

Kubernetes privilege escalation vulnerability

▾ Twilightkubernetes · k8s.io/kubernetesEPSS 13%via OSV
CVE-2023-46239High· 7.5
2y ago

quic-go vulnerable to pointer dereference that can lead to panic

quic-go vulnerable to pointer dereference that can lead to panic

▾ Twilightquic-go · github.com/quic-go/quic-goEPSS 0.77%via OSV
CVE-2021-25736Medium· 5.8
2y ago

Kube-proxy may unintentionally forward traffic

Kube-proxy may unintentionally forward traffic

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.92%via OSV
CVE-2022-4886High· 8.8
2y ago

Ingress-nginx path sanitization can be bypassed

Ingress-nginx path sanitization can be bypassed

▾ Twilightingress-nginx · k8s.io/ingress-nginxEPSS 1.6%via OSV
CVE-2023-5043High· 7.6PoC
2y ago

Ingress nginx annotation injection causes arbitrary command execution

Ingress nginx annotation injection causes arbitrary command execution

▾ Midnightingress-nginx · k8s.io/ingress-nginxEPSS 2.2%via OSV
CVE-2023-43651Medium· 6.4
2y ago

Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell

Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell

▾ Sunlitjumpserver · github.com/jumpserver/kokoEPSS 1.7%via OSV
CVE-2023-47090High
2y ago

NATS.io: Adding accounts for just the system account adds auth bypass

NATS.io: Adding accounts for just the system account adds auth bypass

▾ Twilightnats-io · github.com/nats-io/nats-server/v2EPSS 0.66%via OSV
CVEs tagged “go” — page 49 · VulnSea