GHSA-9763-4F94-GFCH vulnerabilities
Vulnerabilities for packages: vault, aactl, cosign, keda, pulumi, sops, pulumi-kubernetes-operator, flux, flux-notification-controller, pulumi-language-java, actions-runner-controller, kubevela, pulumi-language-yaml, crossplane-provider-aws, flux-image-automation-controller, goreleaser, rclone,...
7.5AI Score
GHSA-C5Q2-7R4C-MV6G vulnerabilities
Vulnerabilities for packages: dex, vault, aactl, nerdctl, cosign, keda, istio-pilot-discovery, frp, istio-cni, istio-pilot-agent, rook, step, falcoctl, containerd, fulcio, dgraph, external-secrets-operator, grpc-health-probe, kargo, ko, gomplate, goreleaser, terragrunt, guac, cilium, minio, tkn,...
7.5AI Score
GHSA-VFP6-JRW2-99G9 vulnerabilities
Vulnerabilities for packages: aactl, skaffold, tkn, cosign, tekton-chains, melange, ko, falco, kubescape, slsa-verifier, policy-controller, goreleaser, apko,...
7.5AI Score
GHSA-3Q2C-PVP5-3CQP vulnerabilities
Vulnerabilities for packages: dex, stakater-reloader, keda, velero, nri-mssql, prometheus-beat-exporter, nri-apache, rqlite, go-bindata, vertical-pod-autoscaler, flux, go-md2man, configmap-reload, yq, newrelic-prometheus-configurator, aws-flb-cloudwatch, dagger, dgraph,...
7.5AI Score
GHSA-J6M3-GC37-6R6Q vulnerabilities
Vulnerabilities for packages: dex, stakater-reloader, keda, velero, nri-mssql, prometheus-beat-exporter, nri-apache, rqlite, go-bindata, vertical-pod-autoscaler, flux, go-md2man, configmap-reload, yq, newrelic-prometheus-configurator, aws-flb-cloudwatch, dagger, dgraph,...
7.5AI Score
GHSA-FGQ5-Q76C-GX78 vulnerabilities
Vulnerabilities for packages: dex, stakater-reloader, keda, velero, nri-mssql, prometheus-beat-exporter, nri-apache, rqlite, go-bindata, vertical-pod-autoscaler, flux, go-md2man, configmap-reload, yq, newrelic-prometheus-configurator, aws-flb-cloudwatch, dagger, dgraph,...
7.5AI Score
Vulnerabilities for packages: aws-ebs-csi-driver, calico, spark-operator, aws-efs-csi-driver, cluster-autoscaler, kubernetes-dns-node-cache, prometheus-adapter, ip-masq-agent,...
8.8CVSS
8.1AI Score
0.001EPSS
GHSA-HQ6Q-C2X6-HMCH vulnerabilities
Vulnerabilities for packages: aws-ebs-csi-driver, calico, spark-operator, aws-efs-csi-driver, cluster-autoscaler, kubernetes-dns-node-cache, prometheus-adapter, ip-masq-agent,...
7.5AI Score
CVE-2024-26147 vulnerabilities
Vulnerabilities for packages: flux-helm-controller, helm-push, chartmuseum, k8sgpt, trivy, up, cert-manager, zarf, istio-operator, cilium-cli, eksctl, kots, kubescape, flux-source-controller, helm-operator, zot,...
7.5CVSS
7.7AI Score
0.0004EPSS
CVE-2024-34064 vulnerabilities
Vulnerabilities for packages: py3-jinja2, confluent-docker-utils, kubeflow-jupyter-web-app, reflex, superset, dask-gateway, pytorch,...
5.4CVSS
6.1AI Score
0.0004EPSS
6.1CVSS
6.8AI Score
0.0004EPSS
9.8CVSS
9.9AI Score
0.005EPSS
CVE-2023-39325 vulnerabilities
Vulnerabilities for packages: coredns, dex, stakater-reloader, cosign, keda, rqlite, kots, falcoctl, vertical-pod-autoscaler, flux, flux-notification-controller, prometheus-stackdriver-exporter, yq, dgraph, nri-prometheus, prometheus-pushgateway, kubernetes-ingress-defaultbackend, trillian,...
7.5CVSS
8.4AI Score
0.002EPSS
CVE-2024-29903 vulnerabilities
Vulnerabilities for packages: aactl, falcoctl, ko, goreleaser, tkn, zarf, melange, falco, kubescape, slsa-verifier, flux-source-controller, policy-controller, neuvector-sigstore-interface, zot, gitsign, tekton-chains, wolfictl, skaffold, apko, spire-server,...
4.2CVSS
4.6AI Score
0.0004EPSS
GHSA-QPPJ-FM5R-HXR3 vulnerabilities
Vulnerabilities for packages: coredns, dex, stakater-reloader, cosign, keda, rqlite, kots, istio-envoy, flux-notification-controller, prometheus-stackdriver-exporter, dgraph, nri-prometheus, ip-masq-agent, nginx-stable, goreleaser, minio, cert-manager, sigstore-scaffolding, envoy-ratelimit,...
7.5AI Score
GHSA-32CH-6X54-Q4H9 vulnerabilities
Vulnerabilities for packages: dex, stakater-reloader, keda, velero, nri-mssql, prometheus-beat-exporter, nri-apache, rqlite, go-bindata, vertical-pod-autoscaler, flux, go-md2man, configmap-reload, yq, newrelic-prometheus-configurator, aws-flb-cloudwatch, dagger, dgraph,...
7.5AI Score
GHSA-MW99-9CHC-XW7R vulnerabilities
Vulnerabilities for packages: go-licenses, pulumi, kots, pulumi-kubernetes-operator, pulumi-language-java, src-fingerprint, kubevela, pulumi-language-yaml, gomplate, goreleaser, pulumi-language-dotnet, bom, flux-kustomize-controller, zot, tekton-pipelines, gitsign, argo-cd, scorecard, gitness,...
7.5AI Score
GHSA-9F76-WG39-X86H vulnerabilities
Vulnerabilities for packages: gosu, go-licenses, aactl, flannel-cni-plugin, nats, render-template, gobuster, hey, k3d, go-bindata, mage, sbom-scorecard, sops, vertical-pod-autoscaler, cilium-envoy, configmap-reload, docker-cli, ctop, go-md2man, aws-flb-cloudwatch, prometheus-stackdriver-exporter,.....
7.5AI Score
CVE-2024-28180 vulnerabilities
Vulnerabilities for packages: dex, vault, aactl, nerdctl, cosign, keda, istio-pilot-discovery, frp, istio-cni, istio-pilot-agent, rook, step, falcoctl, containerd, fulcio, dgraph, external-secrets-operator, grpc-health-probe, kargo, ko, gomplate, goreleaser, terragrunt, guac, cilium, minio, tkn,...
4.3CVSS
6AI Score
0.0005EPSS
GHSA-2WRH-6PVC-2JM9 vulnerabilities
Vulnerabilities for packages: coredns, dex, stakater-reloader, cosign, keda, rqlite, kots, falcoctl, vertical-pod-autoscaler, flux, flux-notification-controller, prometheus-stackdriver-exporter, yq, dgraph, nri-prometheus, prometheus-pushgateway, trillian, goreleaser, prometheus-postgres-exporter,....
7.5AI Score
GHSA-45X7-PX36-X8W8 vulnerabilities
Vulnerabilities for packages: coredns, dex, cosign, cilium-cli, nri-mssql, rqlite, kots, falcoctl, flux, fulcio, prometheus-stackdriver-exporter, dgraph, trillian, goreleaser, kubernetes-event-exporter, prometheus-postgres-exporter, certificate-transparency, cfssl, temporal-ui-server, tkn,...
7.5AI Score
GHSA-V53G-5GJP-272R vulnerabilities
Vulnerabilities for packages: flux-helm-controller, helm-push, chartmuseum, k8sgpt, trivy, up, cert-manager, zarf, istio-operator, cilium-cli, eksctl, kots, kubescape, flux-source-controller, helm-operator, zot,...
7.5AI Score
7.5AI Score
9.8CVSS
9.9AI Score
0.005EPSS
9.8CVSS
9.9AI Score
0.005EPSS
7.5AI Score
GHSA-4374-P667-P6C8 vulnerabilities
Vulnerabilities for packages: coredns, dex, stakater-reloader, cosign, keda, rqlite, kots, falcoctl, vertical-pod-autoscaler, flux, flux-notification-controller, prometheus-stackdriver-exporter, yq, dgraph, nri-prometheus, prometheus-pushgateway, kubernetes-ingress-defaultbackend, trillian,...
7.5AI Score
GHSA-M425-MQ94-257G vulnerabilities
Vulnerabilities for packages: coredns, dex, aactl, flux-helm-controller, helm, aws-efs-csi-driver, cosign, keda, prometheus-adapter, pulumi, nvidia-device-plugin, grype, prometheus-blackbox-exporter, k3d, kots, pulumi-kubernetes-operator, cilium-envoy, flux-notification-controller,...
7.5AI Score
CVE-2024-29902 vulnerabilities
Vulnerabilities for packages: aactl, falcoctl, ko, goreleaser, tkn, zarf, melange, falco, kubescape, slsa-verifier, flux-source-controller, policy-controller, neuvector-sigstore-interface, zot, gitsign, tekton-chains, wolfictl, skaffold, apko, spire-server,...
4.2CVSS
4.5AI Score
0.0004EPSS
CVE-2024-37891 vulnerabilities
Vulnerabilities for packages: airflow, confluent-docker-utils, k8s-sidecar, kubeflow-jupyter-web-app, kubeflow-pipelines, py3-urllib3, ggshield, reflex, superset, py3-cassandra-medusa, az, dask-gateway, kubeflow-katib, kubeflow-volumes-web-app,...
4.4CVSS
4.9AI Score
0.0004EPSS
GHSA-49GW-VXVF-FC2G vulnerabilities
Vulnerabilities for packages: falcosidekick, nri-mssql, ghaudit, flux, yq, newrelic-prometheus-configurator, dgraph, kubeadm-controlplane-controller, ip-masq-agent, kubernetes-ingress-defaultbackend, trillian, php-fpm_exporter, cfssl, metallb, buildkitd, loki, task, gitness,...
7.5AI Score
GHSA-5F94-VHJQ-RPG8 vulnerabilities
Vulnerabilities for packages: gosu, go-licenses, aactl, flannel-cni-plugin, nats, render-template, gobuster, hey, k3d, go-bindata, mage, sbom-scorecard, sops, vertical-pod-autoscaler, cilium-envoy, configmap-reload, docker-cli, ctop, go-md2man, aws-flb-cloudwatch, prometheus-stackdriver-exporter,.....
7.5AI Score
CVE-2023-39326 vulnerabilities
Vulnerabilities for packages: gosu, go-licenses, aactl, flannel-cni-plugin, nats, render-template, gobuster, hey, k3d, go-bindata, mage, sbom-scorecard, sops, vertical-pod-autoscaler, cilium-envoy, configmap-reload, docker-cli, ctop, go-md2man, aws-flb-cloudwatch, prometheus-stackdriver-exporter,.....
5.3CVSS
7.2AI Score
0.001EPSS
CVE-2024-24783 vulnerabilities
Vulnerabilities for packages: dex, stakater-reloader, keda, velero, nri-mssql, prometheus-beat-exporter, nri-apache, rqlite, go-bindata, vertical-pod-autoscaler, flux, go-md2man, configmap-reload, yq, newrelic-prometheus-configurator, aws-flb-cloudwatch, dagger, dgraph,...
7.9AI Score
0.0004EPSS
CVE-2024-24785 vulnerabilities
Vulnerabilities for packages: dex, stakater-reloader, keda, velero, nri-mssql, prometheus-beat-exporter, nri-apache, rqlite, go-bindata, vertical-pod-autoscaler, flux, go-md2man, configmap-reload, yq, newrelic-prometheus-configurator, aws-flb-cloudwatch, dagger, dgraph,...
7.8AI Score
0.0004EPSS
CVE-2024-24788 vulnerabilities
Vulnerabilities for packages: coredns, dex, falcosidekick, nvidia-container-toolkit, harbor-scanner-trivy, cosign, cilium-cli, mkcert, prometheus-beat-exporter, go-bindata, spicedb, falcoctl, ghaudit, vertical-pod-autoscaler, configmap-reload, flux-notification-controller, fulcio, go-md2man,...
6.5AI Score
0.0004EPSS
GHSA-236W-P7WF-5PH8 vulnerabilities
Vulnerabilities for packages: falcosidekick, nri-mssql, ghaudit, flux, yq, newrelic-prometheus-configurator, dgraph, kubeadm-controlplane-controller, ip-masq-agent, kubernetes-ingress-defaultbackend, trillian, php-fpm_exporter, cfssl, metallb, buildkitd, loki, task, gitness,...
7.5AI Score
GHSA-XW73-RW38-6VJC vulnerabilities
Vulnerabilities for packages: aactl, flux-helm-controller, helm, cosign, nerdctl, cri-tools, pulumi, istio-pilot-discovery, eksctl, istio-pilot-agent, kots, flux-image-reflector-controller, traefik, falcoctl, cadvisor, timoni, ctop, k3s, dagger, crane, k8sgpt, kargo, kubevela, scorecard,...
7.5AI Score
7.5AI Score
GHSA-34JH-P97F-MPXF vulnerabilities
Vulnerabilities for packages: airflow, confluent-docker-utils, k8s-sidecar, kubeflow-jupyter-web-app, kubeflow-pipelines, py3-urllib3, ggshield, reflex, superset, py3-cassandra-medusa, az, dask-gateway, kubeflow-katib, kubeflow-volumes-web-app,...
7.5AI Score
CVE-2023-49568 vulnerabilities
Vulnerabilities for packages: go-licenses, pulumi, kots, pulumi-kubernetes-operator, pulumi-language-java, src-fingerprint, kubevela, pulumi-language-yaml, gomplate, goreleaser, pulumi-language-dotnet, bom, flux-kustomize-controller, zot, tekton-pipelines, gitsign, argo-cd, scorecard, gitness,...
7.5CVSS
7.8AI Score
0.0005EPSS
GHSA-PXHW-596R-RWQ5 vulnerabilities
Vulnerabilities for packages: aws-ebs-csi-driver, calico, spark-operator, cluster-autoscaler, kubernetes-csi-driver-hostpath, kubernetes-dns-node-cache, ip-masq-agent, node-feature-discovery, nodetaint, local-static-provisioner,...
7.5AI Score
GHSA-XR7R-F8XQ-VFVV vulnerabilities
Vulnerabilities for packages: nerdctl, syft, docker, nvidia-device-plugin, grype, k3d, kots, cadvisor, ctop, k3s, kubernetes, newrelic-infrastructure-agent, trivy, zarf, kubescape, zot, runc, ingress-nginx-controller, telegraf, datadog-agent, kaniko, buildkitd, skopeo, wolfictl, skaffold,...
7.5AI Score
GHSA-V845-JXX5-VC9F vulnerabilities
Vulnerabilities for packages: k8s-sidecar, kubeflow-jupyter-web-app, py3-urllib3, dask-gateway, kubeflow-volumes-web-app,...
7.5AI Score
CVE-2023-43804 vulnerabilities
Vulnerabilities for packages: k8s-sidecar, kubeflow-jupyter-web-app, py3-urllib3, dask-gateway, kubeflow-volumes-web-app,...
8.1CVSS
7.7AI Score
0.001EPSS
CVE-2023-45290 vulnerabilities
Vulnerabilities for packages: dex, stakater-reloader, keda, velero, nri-mssql, prometheus-beat-exporter, nri-apache, rqlite, go-bindata, vertical-pod-autoscaler, flux, go-md2man, configmap-reload, yq, newrelic-prometheus-configurator, aws-flb-cloudwatch, dagger, dgraph,...
6AI Score
0.0004EPSS
CVE-2021-4235 affecting package application-gateway-kubernetes-ingress 1.4.0-20
CVE-2021-4235 affecting package application-gateway-kubernetes-ingress 1.4.0-20. This CVE either no longer is or was never...
5.5CVSS
6.3AI Score
0.001EPSS
CVE-2022-3064 affecting package application-gateway-kubernetes-ingress 1.4.0-20
CVE-2022-3064 affecting package application-gateway-kubernetes-ingress 1.4.0-20. This CVE either no longer is or was never...
7.5CVSS
7.9AI Score
0.005EPSS
CVE-2023-44487 affecting package application-gateway-kubernetes-ingress for versions less than 1.4.0-15. A patched version of the package is...
7.5CVSS
8.2AI Score
0.732EPSS
Security Bulletin: IBM Automation Decision Services for May 2024 - Multiple CVEs addressed
Summary "IBM Automation Decision Services is vulnerable to multiple remote code execution and denial of service attacks in third party and open source used in the product for various functions. See full list below. The vulnerabilities have been addressed." Vulnerability Details ** CVEID:...
7.5CVSS
8.8AI Score
0.001EPSS