VulnSea

Tagged “go”

CVEs tagged go, newest first.

1746 CVEsRSS

CVE-2023-3978Medium· 6.1
3y ago

Improper rendering of text nodes in golang.org/x/net/html

Improper rendering of text nodes in golang.org/x/net/html

▾ Sunlitx · golang.org/x/netEPSS 0.85%via OSV
CVE-2023-37900Low· 3.4
3y ago

Denial of service from large image

Denial of service from large image

▾ Sunlitcrossplane · github.com/crossplane/crossplaneEPSS 0.62%via OSV
CVE-2023-37916Medium· 6.5
3y ago

KubePi may leak password hash of any user

KubePi may leak password hash of any user

▾ SunlitKubeOperator · github.com/KubeOperator/kubepiEPSS 0.81%via OSV
CVE-2023-37917Critical· 9.1
3y ago

KubePi Privilege Escalation vulnerability

KubePi Privilege Escalation vulnerability

▾ MidnightKubeOperator · github.com/KubeOperator/kubepiEPSS 0.74%via OSV
CVE-2023-37918Medium· 6.8
3y ago

Dapr API token authentication bypass in HTTP endpoints

Dapr API token authentication bypass in HTTP endpoints

▾ Sunlitdapr · github.com/dapr/daprEPSS 1.4%via OSV
CVE-2023-37788High· 7.5
3y ago

goproxy Denial of Service vulnerability

goproxy Denial of Service vulnerability

▾ Twilightelazarl · github.com/elazarl/goproxyEPSS 0.98%via OSV
CVE-2023-34236High· 8.5
3y ago

Weave GitOps Terraform Controller Information Disclosure Vulnerability

Weave GitOps Terraform Controller Information Disclosure Vulnerability

▾ Twilightweaveworks · github.com/weaveworks/tf-controllerEPSS 0.96%via OSV
GHSA-2w8w-qhg4-f78jMedium· 6.5
3y ago

A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries

A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries

▾ Sunlitjaegertracing · github.com/jaegertracing/jaegervia OSV
CVE-2023-36458Medium· 6.3
3y ago

1Panel vulnerable to command injection when entering the container terminal

1Panel vulnerable to command injection when entering the container terminal

▾ Sunlit1Panel-dev · github.com/1Panel-dev/1PanelEPSS 2.3%via OSV
CVE-2023-3128Critical· 9.4PoC
3y ago

Grafana vulnerable to Authentication Bypass by Spoofing

Grafana vulnerable to Authentication Bypass by Spoofing

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 4.0%via OSV
CVE-2023-34758High· 8.1
3y ago

Silver vulnerable to MitM attack against implants due to a cryptography vulnerability

Silver vulnerable to MitM attack against implants due to a cryptography vulnerability

▾ Twilightbishopfox · github.com/bishopfox/sliverEPSS 0.59%via OSV
CVE-2023-2183Medium· 4.1
3y ago

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.0%via OSV
CVE-2023-33967High· 8.2
3y ago

SQL injection when using MySQL/PostgreSQL data checking

SQL injection when using MySQL/PostgreSQL data checking

▾ Twilightmegaease · github.com/megaease/easeprobeEPSS 0.66%via OSV
CVE-2023-2801High· 7.5
3y ago

Grafana Missing Synchronization vulnerability

Grafana Missing Synchronization vulnerability

▾ Twilightgrafana · github.com/grafana/grafanaEPSS 0.74%via OSV
CVE-2023-22647Critical· 9.9
3y ago

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2020-10676High· 8.8
3y ago

Rancher users retain access after moving namespaces into projects they don't have access to

Rancher users retain access after moving namespaces into projects they don't have access to

▾ Twilightrancher · github.com/rancher/rancherEPSS 1.0%via OSV
CVE-2022-43760High· 8.4
3y ago

Rancher UI has multiple Cross-Site Scripting (XSS) issues

Rancher UI has multiple Cross-Site Scripting (XSS) issues

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2023-34091Medium· 6.5
3y ago

Kyverno resource with a deletionTimestamp may allow policy circumvention

Kyverno resource with a deletionTimestamp may allow policy circumvention

▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.50%via OSV
CVE-2023-33964High· 8.6
3y ago

mx-chain-go does not treat invalid transaction with wrong username correctly

mx-chain-go does not treat invalid transaction with wrong username correctly

▾ Twilightmultiversx · github.com/multiversx/mx-chain-goEPSS 0.57%via OSV
GHSA-hgv6-w7r3-w4qwMedium
3y ago

Kyverno vulnerable due to usage of insecure cipher

Kyverno vulnerable due to usage of insecure cipher

▾ Sunlitkyverno · github.com/kyverno/kyvernovia OSV
CVE-2023-33191Medium· 4.6
3y ago

kyverno seccomp control can be circumvented

kyverno seccomp control can be circumvented

▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.48%via OSV
CVE-2023-32698High· 7.1
3y ago

nfpm has incorrect default permissions

nfpm has incorrect default permissions

▾ Twilightgoreleaser · github.com/goreleaser/nfpm/v2EPSS 0.38%via OSV
CVE-2021-25748Medium· 6.5
3y ago

Ingress-nginx `path` sanitization can be bypassed with newline character

Ingress-nginx `path` sanitization can be bypassed with newline character

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 0.69%via OSV
CVE-2023-30851Medium· 5.3
3y ago

Potential HTTP policy bypass when using header rules in Cilium

Potential HTTP policy bypass when using header rules in Cilium

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.66%via OSV
CVE-2023-32082Low· 3.1
3y ago

etcd Key name can be accessed via LeaseTimeToLive API

etcd Key name can be accessed via LeaseTimeToLive API

▾ Sunlitetcd-io · github.com/etcd-io/etcdEPSS 0.74%via OSV
CVE-2023-1732Medium· 5.3
3y ago

Improper random reading in CIRCL

Improper random reading in CIRCL

▾ Sunlitcloudflare · github.com/cloudflare/circlEPSS 0.39%via OSV
CVE-2023-30551High· 7.5
3y ago

Rekor's compressed archives can result in OOM conditions

Rekor's compressed archives can result in OOM conditions

▾ Twilightsigstore · github.com/sigstore/rekorEPSS 1.1%via OSV
CVE-2023-22651Critical· 9.9
3y ago

Rancher Webhook is misconfigured during upgrade process

Rancher Webhook is misconfigured during upgrade process

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.78%via OSV
CVE-2023-30622Medium· 6.7
3y ago

A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation

A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation

▾ Sunlitclusternet · github.com/clusternet/clusternetEPSS 0.19%via OSV
CVE-2023-29013High· 7.5
3y ago

Traefik HTTP header parsing could cause a denial of service

Traefik HTTP header parsing could cause a denial of service

▾ Twilighttraefik · github.com/traefik/traefik/v2EPSS 1.1%via OSV
CVEs tagged “go” — page 51 · VulnSea