VulnSea

Tagged “go”

CVEs tagged go, newest first.

1746 CVEsRSS

CVE-2021-43839High· 7.5
4y ago

Drainage of FeeCollector's Block Transaction Fees in cronos

Drainage of FeeCollector's Block Transaction Fees in cronos

▾ Twilightcrypto-org-chain · github.com/crypto-org-chain/cronosEPSS 1.3%via OSV
CVE-2020-5233Medium· 5.9
4y ago

The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect

The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect

▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxyEPSS 1.3%via OSV
CVE-2020-13845High· 7.5
4y ago

Execution Control List (ECL) Is Insecure in Singularity

Execution Control List (ECL) Is Insecure in Singularity

▾ Twilightsylabs · github.com/sylabs/singularityEPSS 0.52%via OSV
CVE-2020-13846High· 7.5
4y ago

"Verify All" Returns Success Despite Validation Failures in Singularity

"Verify All" Returns Success Despite Validation Failures in Singularity

▾ Twilightsylabs · github.com/sylabs/singularityEPSS 1.3%via OSV
CVE-2020-15091Medium· 6.5
4y ago

Denial of Service in TenderMint

Denial of Service in TenderMint

▾ Sunlittendermint · github.com/tendermint/tendermintEPSS 0.91%via OSV
CVE-2021-32637Critical· 10.0
4y ago

Authelia vulnerable to an authentication bypassed with malformed request URI on nginx

Authelia vulnerable to an authentication bypassed with malformed request URI on nginx

▾ Midnightauthelia · github.com/authelia/authelia/v4EPSS 1.9%via OSV
CVE-2020-5415High· 7.5
4y ago

GitLab auth uses full name instead of username as user ID, allowing impersonation

GitLab auth uses full name instead of username as user ID, allowing impersonation

▾ Twilightconcourse · github.com/concourse/concourseEPSS 1.2%via OSV
CVE-2020-4037Medium· 4.3
4y ago

Open Redirect in OAuth2 Proxy

Open Redirect in OAuth2 Proxy

▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxyEPSS 0.90%via OSV
CVE-2020-26290Critical· 9.8
4y ago

Authentication Bypass in dex

Authentication Bypass in dex

▾ Midnightdexidp · github.com/dexidp/dexEPSS 0.99%via OSV
CVE-2021-39183High· 8.2
4y ago

Unsafe inline XSS in pasting DOM element into chat

Unsafe inline XSS in pasting DOM element into chat

▾ Twilightowncast · github.com/owncast/owncastEPSS 0.75%via OSV
CVE-2021-41090Medium· 6.5
4y ago

Instance config inline secret exposure in Grafana

Instance config inline secret exposure in Grafana

▾ Sunlitgrafana · github.com/grafana/agentEPSS 0.74%via OSV
CVE-2021-43784Medium· 6.0
4y ago

Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC

Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC

▾ Sunlitopencontainers · github.com/opencontainers/runcEPSS 1.7%via OSV
CVE-2021-41278Medium· 5.4PoC
4y ago

Broken encryption in EdgeX Foundry

Broken encryption in EdgeX Foundry

▾ Twilightedgexfoundry · github.com/edgexfoundry/app-functions-sdk-go/v2EPSS 0.32%via OSV
GHSA-77vh-xpmg-72qhLow· 3.0
4y ago

Clarify `mediaType` handling

Clarify `mediaType` handling

▾ Sunlitopencontainers · github.com/opencontainers/image-specvia OSV
GHSA-5j5w-g665-5m35Low· 3.0
4y ago

Ambiguous OCI manifest parsing

Ambiguous OCI manifest parsing

▾ Sunlitcontainerd · github.com/containerd/containerdvia OSV
CVE-2021-41190Low· 3.0
4y ago

Clarify Content-Type handling

Clarify Content-Type handling

▾ Sunlitopencontainers · github.com/opencontainers/distribution-specEPSS 2.2%via OSV
CVE-2021-41254High· 8.8
4y ago

Privilege escalation to cluster admin on multi-tenant environments

Privilege escalation to cluster admin on multi-tenant environments

▾ Twilightfluxcd · github.com/fluxcd/kustomize-controllerEPSS 1.8%via OSV
CVE-2021-22565Medium· 6.5
4y ago

Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server

Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server

▾ Sunlitgoogle · github.com/google/exposure-notifications-verification-serverEPSS 0.43%via OSV
CVE-2021-3911Medium· 4.2
4y ago

Misconfigured IP address field in ROA leads to OctoRPKI crash

Misconfigured IP address field in ROA leads to OctoRPKI crash

▾ Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.91%via OSV
CVE-2021-41230Medium· 5.3
4y ago

OIDC claims not updated from Identity Provider in Pomerium

OIDC claims not updated from Identity Provider in Pomerium

▾ Sunlitpomerium · github.com/pomerium/pomeriumEPSS 0.86%via OSV
CVE-2021-3912Medium· 4.2
4y ago

OctoRPKI crashes when processing GZIP bomb returned via malicious repository

OctoRPKI crashes when processing GZIP bomb returned via malicious repository

▾ Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.85%via OSV
CVE-2021-3908Medium· 5.9
4y ago

Infinite certificate chain depth results in OctoRPKI running forever

Infinite certificate chain depth results in OctoRPKI running forever

▾ Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.73%via OSV
CVE-2021-3909Medium· 4.4
4y ago

Infinite open connection causes OctoRPKI to hang forever

Infinite open connection causes OctoRPKI to hang forever

▾ Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 1.6%via OSV
CVE-2021-3910High· 7.5
4y ago

NUL character in ROA causes OctoRPKI to crash

NUL character in ROA causes OctoRPKI to crash

▾ Twilightcloudflare · github.com/cloudflare/cfrpkiEPSS 1.3%via OSV
CVE-2021-41232High· 8.1
4y ago

Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker

Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker

▾ Twilightstevenweathers · github.com/stevenweathers/thunderdome-planning-pokerEPSS 1.5%via OSV
CVE-2021-41173Medium· 5.7
4y ago

Geth Node Vulnerable to DoS via maliciously crafted p2p message

Geth Node Vulnerable to DoS via maliciously crafted p2p message

▾ Sunlitethereum · github.com/ethereum/go-ethereumEPSS 1.2%via OSV
CVE-2021-41135Medium· 6.5
4y ago

Authz Module Non-Determinism

Authz Module Non-Determinism

▾ Sunlitcosmos · github.com/cosmos/cosmos-sdkEPSS 1.7%via OSV
CVE-2021-39226High· 7.3CISA KEVPoC
4y ago

Authentication bypass for viewing and deletions of snapshots

Authentication bypass for viewing and deletions of snapshots

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 100%via OSV
CVE-2021-41103Medium· 5.9
4y ago

Insufficiently restricted permissions on plugin directories

Insufficiently restricted permissions on plugin directories

▾ Sunlitcontainerd · github.com/containerd/containerdEPSS 0.52%via OSV
CVE-2021-41088High· 8.0
5y ago

Elvish vulnerable to remote code execution via the web UI backend

Elvish vulnerable to remote code execution via the web UI backend

▾ Twilightelves · github.com/elves/elvishEPSS 0.54%via OSV
CVEs tagged “go” — page 56 · VulnSea