VulnSea

Tagged “go”

CVEs tagged go, newest first.

1746 CVEsRSS

CVE-2022-27649High· 7.5
4y ago

Podman's default inheritable capabilities for linux container not empty

Podman's default inheritable capabilities for linux container not empty

▾ Twilightcontainers · github.com/containers/podman/v4EPSS 1.4%via OSV
CVE-2022-27651Medium· 6.8
4y ago

Non-empty default inheritable capabilities for linux container in Buildah

Non-empty default inheritable capabilities for linux container in Buildah

▾ Sunlitcontainers · github.com/containers/buildahEPSS 1.3%via OSV
CVE-2022-1025Critical· 9.9
4y ago

Improper access control allows admin privilege escalation in Argo CD

Improper access control allows admin privilege escalation in Argo CD

▾ Midnightargoproj · github.com/argoproj/argo-cdEPSS 1.3%via OSV
CVE-2022-21221High· 7.5
4y ago

Path traversal in github.com/valyala/fasthttp

Path traversal in github.com/valyala/fasthttp

▾ Twilightvalyala · github.com/valyala/fasthttpEPSS 2.5%via OSV
CVE-2022-0811High· 8.8PoC
4y ago

Code Injection in CRI-O

Code Injection in CRI-O

▾ Midnightcri-o · github.com/cri-o/cri-oEPSS 19%via OSV
CVE-2022-26652Medium· 6.5
4y ago

Arbitrary file write in nats-server

Arbitrary file write in nats-server

▾ Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 2.3%via OSV
CVE-2020-8552Medium· 5.3
4y ago

Kubernetes API Server DoS Via API Requests

Kubernetes API Server DoS Via API Requests

▾ Sunlitapiserver · k8s.io/apiserverEPSS 2.4%via OSV
CVE-2021-3127Critical
4y ago

nats-io/jwt not enforcing checking of Import token permissions

nats-io/jwt not enforcing checking of Import token permissions

▾ Midnightnats-io · github.com/nats-io/jwtEPSS 1.4%via OSV
CVE-2018-1002207Medium· 5.5
4y ago

Arbitrary File Write via Archive Extraction in mholt/archiver

Arbitrary File Write via Archive Extraction in mholt/archiver

▾ Sunlitmholt · github.com/mholt/archiverEPSS 2.5%via OSV
CVE-2018-1002105Critical· 9.8PoC
4y ago

Privilege Escalation in Kubernetes

Privilege Escalation in Kubernetes

▾ Abyssalkubernetes · github.com/kubernetes/kubernetesEPSS 87%via OSV
CVE-2019-1002101Medium· 5.5PoC
4y ago

Symlink Attack in kubectl cp

Symlink Attack in kubectl cp

▾ Twilightkubernetes · k8s.io/kubernetesEPSS 13%via OSV
CVE-2020-8551Medium· 4.3
4y ago

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 1.2%via OSV
CVE-2020-13597Medium· 6.0
4y ago

Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico

Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico

▾ Sunlitprojectcalico · github.com/projectcalico/calicoEPSS 0.90%via OSV
CVE-2020-28466High· 7.5
4y ago

Denial of service in github.com/nats-io/nats-server/server

Denial of service in github.com/nats-io/nats-server/server

▾ Twilightnats-io · github.com/nats-io/nats-serverEPSS 3.7%via OSV
CVE-2020-26294High· 7.4
4y ago

Exposure of server configuration in github.com/go-vela/server

Exposure of server configuration in github.com/go-vela/server

▾ Twilightgo-vela · github.com/go-vela/compilerEPSS 1.8%via OSV
CVE-2021-21272High· 7.7
4y ago

Zip slip directory exploit in github.com/deislabs/oras

Zip slip directory exploit in github.com/deislabs/oras

▾ Twilightdeislabs · github.com/deislabs/orasEPSS 1.4%via OSV
CVE-2021-21237High· 7.2
4y ago

Git LFS can execute a Git binary from the current directory on Windows

Git LFS can execute a Git binary from the current directory on Windows

▾ Twilightgit-lfs · github.com/git-lfs/git-lfsEPSS 0.43%via OSV
CVE-2021-29136Medium· 5.5
4y ago

Improper input validation in umoci

Improper input validation in umoci

▾ Sunlitopencontainers · github.com/opencontainers/umociEPSS 0.34%via OSV
CVE-2021-21403High· 7.5
4y ago

Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/server

Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/server

▾ Twilightkongchuanhujiao · github.com/kongchuanhujiao/serverEPSS 1.4%via OSV
CVE-2021-21432High· 7.5
4y ago

Reject unauthorized access with GitHub PATs

Reject unauthorized access with GitHub PATs

▾ Twilightgo-vela · github.com/go-vela/serverEPSS 0.99%via OSV
CVE-2020-26277Medium· 6.1
4y ago

Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployer

Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployer

▾ Sunlitdatacharmer · github.com/datacharmer/dbdeployerEPSS 1.2%via OSV
CVE-2020-29662Medium· 5.3
4y ago

"catalog's registry v2 api exposed on unauthenticated path in Harbor"

"catalog's registry v2 api exposed on unauthenticated path in Harbor"

▾ Sunlitgoharbor · github.com/goharbor/harborEPSS 0.72%via OSV
CVE-2020-8912Low· 2.5
4y ago

In-band key negotiation issue in AWS S3 Crypto SDK for golang

In-band key negotiation issue in AWS S3 Crypto SDK for golang

▾ Sunlitaws · github.com/aws/aws-sdk-goEPSS 0.23%via OSV
CVE-2020-15157Medium· 6.1
4y ago

containerd v1.2.x can be coerced into leaking credentials during image pull

containerd v1.2.x can be coerced into leaking credentials during image pull

▾ Sunlitcontainerd · github.com/containerd/containerdEPSS 2.3%via OSV
CVE-2020-26892Critical· 9.8
4y ago

Incorrect handling of credential expiry by /nats-io/nats-server

Incorrect handling of credential expiry by /nats-io/nats-server

▾ Midnightnats-io · github.com/nats-io/jwtEPSS 2.1%via OSV
CVE-2020-15129Medium· 6.1PoC
4y ago

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

▾ Twilighttraefik · github.com/traefik/traefikEPSS 8.0%via OSV
CVE-2020-8918High· 7.1
4y ago

TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm

TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm

▾ Twilightgoogle · github.com/google/go-tpmEPSS 0.18%via OSV
GHSA-qq97-vm5h-rrhgLow· 3.0
4y ago

OCI Manifest Type Confusion Issue

OCI Manifest Type Confusion Issue

▾ Sunlitdocker · github.com/docker/distributionvia OSV
CVE-2022-24348High· 7.7PoC
4y ago

Path traversal and dereference of symlinks in Argo CD

Path traversal and dereference of symlinks in Argo CD

▾ Midnightargoproj · github.com/argoproj/argo-cd/v2EPSS 2.7%via OSV
CVE-2021-43816High· 8.0
4y ago

Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux

Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux

▾ Twilightcontainerd · github.com/containerd/containerdEPSS 1.7%via OSV
CVEs tagged “go” — page 55 · VulnSea