VulnSea

Tagged “go”

CVEs tagged go, newest first.

1746 CVEsRSS

CVE-2023-43802High· 7.3
2y ago

Arduino Create Agent path traversal - local privilege escalation vulnerability

Arduino Create Agent path traversal - local privilege escalation vulnerability

▾ Twilightarduino · github.com/arduino/arduino-create-agentEPSS 0.35%via OSV
CVE-2023-43800High· 7.3
2y ago

Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability

Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability

▾ Twilightarduino · github.com/arduino/arduino-create-agentEPSS 0.21%via OSV
CVE-2023-45683High· 7.1
2y ago

Cross-site Scripting via missing Binding syntax validation

Cross-site Scripting via missing Binding syntax validation

▾ Twilightcrewjam · github.com/crewjam/samlEPSS 0.43%via OSV
CVE-2023-4822Medium· 6.7
2y ago

grafana: incorrect assessment of permissions across organizations (CVE-2023-4822)

A flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permis…

▾ SunlitRed Hat · Red Hat Ceph Storage 7.1 ToolsEPSS 1.1%via CSAF
CVE-2023-39325High· 7.5PoC
2y ago

HTTP/2 rapid reset can cause excessive work in net/http

HTTP/2 rapid reset can cause excessive work in net/http

▾ Midnightx · golang.org/x/netEPSS 3.8%via OSV
CVE-2023-20902Medium· 5.9
2y ago

Harbor timing attack risk

Harbor timing attack risk

▾ Sunlitgoharbor · github.com/goharbor/harborEPSS 0.37%via OSV
CVE-2023-32188Critical
2y ago

JWT token compromise can allow malicious actions including Remote Code Execution (RCE)

JWT token compromise can allow malicious actions including Remote Code Execution (RCE)

▾ Midnightneuvector · github.com/neuvector/neuvectorEPSS 0.48%via OSV
CVE-2023-44378Medium· 5.5
2y ago

gnark unsoundness in variable comparison / non-unique binary decomposition

gnark unsoundness in variable comparison / non-unique binary decomposition

▾ Sunlitconsensys · github.com/consensys/gnarkEPSS 0.22%via OSV
CVE-2023-5077High· 7.6
3y ago

Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability

Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.44%via OSV
CVE-2023-43645Medium· 5.9
3y ago

OpenFGA Vulnerable to DoS from circular relationship definitions

OpenFGA Vulnerable to DoS from circular relationship definitions

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.75%via OSV
CVE-2023-40026Medium· 5.0
3y ago

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

▾ Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.50%via OSV
CVE-2023-41333Medium· 6.9
3y ago

Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy

Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.41%via OSV
CVE-2023-41332Low· 3.5
3y ago

Specific Cilium configurations vulnerable to DoS via Kubernetes annotations

Specific Cilium configurations vulnerable to DoS via Kubernetes annotations

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.45%via OSV
CVE-2022-3962Medium· 4.3
3y ago

Kiali content spoofing vulnerability

Kiali content spoofing vulnerability

▾ Sunlitkiali · github.com/kiali/kialiEPSS 0.74%via OSV
CVE-2023-43621Medium· 4.7
3y ago

Croc may expose secret to local users

Croc may expose secret to local users

▾ Sunlitschollz · github.com/schollz/croc/v9EPSS 0.31%via OSV
CVE-2023-43618Medium· 5.3
3y ago

Croc requires senders to provide local IP addresses in cleartext

Croc requires senders to provide local IP addresses in cleartext

▾ Sunlitschollz · github.com/schollz/croc/v9EPSS 0.49%via OSV
CVE-2023-43620High· 7.8
3y ago

Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device

Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device

▾ Twilightschollz · github.com/schollz/croc/v9EPSS 0.36%via OSV
CVE-2023-4680Medium· 6.8
3y ago

HashiCorp Vault Improper Input Validation vulnerability

HashiCorp Vault Improper Input Validation vulnerability

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.44%via OSV
CVE-2023-41318Medium· 4.1
3y ago

matrix-media-repo: Unsafe media served inline on download endpoints

matrix-media-repo: Unsafe media served inline on download endpoints

▾ Sunlitturt2live · github.com/turt2live/matrix-media-repoEPSS 0.52%via OSV
CVE-2023-41338Medium· 5.3
3y ago

Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`

Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`

▾ Sunlitgofiber · github.com/gofiber/fiberEPSS 0.66%via OSV
GHSA-6xv5-86q9-7xr8Medium
3y ago

SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced

SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced

▾ Sunlitcyphar · github.com/cyphar/filepath-securejoinvia OSV
GHSA-23px-mw2p-46qmMedium
3y ago

Cosmos-SDK Cosmovisor component may be vulnerable to denial of service

Cosmos-SDK Cosmovisor component may be vulnerable to denial of service

▾ Sunlitcosmos · github.com/cosmos/cosmos-sdkvia OSV
CVE-2023-28434High· 8.8CISA KEVPoC
3y ago

Privilege Escalation on Linux/MacOS

Privilege Escalation on Linux/MacOS

▾ Abyssalminio · github.com/minio/minioEPSS 7.9%via OSV
CVE-2023-32079High· 8.8
3y ago

Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User

Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User

▾ Twilightgravitl · github.com/gravitl/netmakerEPSS 0.86%via OSV
CVE-2023-32078High· 7.5
3y ago

Netmaker IDOR Allows User to Update Other User's Password

Netmaker IDOR Allows User to Update Other User's Password

▾ Twilightgravitl · github.com/gravitl/netmakerEPSS 0.70%via OSV
CVE-2023-38976High· 7.5
3y ago

Weaviate denial of service vulnerability

Weaviate denial of service vulnerability

▾ Twilightweaviate · github.com/weaviate/weaviateEPSS 2.1%via OSV
CVE-2023-40034High· 8.1
3y ago

Woodpecker does not validate webhook before changing any data

Woodpecker does not validate webhook before changing any data

▾ Twilightwoodpecker-ci · github.com/woodpecker-ci/woodpeckerEPSS 0.88%via OSV
CVE-2023-39965Medium· 6.5
3y ago

1Panel Arbitrary File Download vulnerability

1Panel Arbitrary File Download vulnerability

▾ Sunlit1Panel-dev · github.com/1Panel-dev/1PanelEPSS 0.44%via OSV
CVE-2023-3518High· 7.4
3y ago

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers

▾ Twilighthashicorp · github.com/hashicorp/consulEPSS 0.45%via OSV
CVE-2023-37896High· 7.5
3y ago

Nuclei Path Traversal vulnerability

Nuclei Path Traversal vulnerability

▾ Twilightprojectdiscovery · github.com/projectdiscovery/nuclei/v2EPSS 1.0%via OSV
CVEs tagged “go” — page 50 · VulnSea