Lucene search

K

Galaxy Book Go, Galaxy Book Go 5G, Galaxy Book2 Go And Galaxy Book2 Pro 360 Security Vulnerabilities

osv
osv

Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core' in github.com/rancher/rancher

Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core' in...

6.9AI Score

EPSS

2024-06-28 03:28 PM
1
osv
osv

Etcd embed auto compaction retention negative value causing a compaction loop or a crash in go.etcd.io/etcd

Etcd embed auto compaction retention negative value causing a compaction loop or a crash in...

7.1AI Score

2024-06-28 03:28 PM
osv
osv

Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers in github.com/dexidp/dex

Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers in...

7.5CVSS

6.7AI Score

0.001EPSS

2024-06-28 03:28 PM
osv

6.1CVSS

6.4AI Score

0.0005EPSS

2024-06-28 03:28 PM
osv
osv

HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault

HashiCorp Vault Improper Privilege Management in...

9.1CVSS

6.7AI Score

0.002EPSS

2024-06-28 03:28 PM
1
osv
osv

Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation in k8s.io/ingress-nginx

Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation in...

8.8CVSS

7.2AI Score

0.001EPSS

2024-06-28 03:28 PM
1
osv
osv

Grafana XSS via a query alias for the ElasticSearch datasource in github.com/grafana/grafana

Grafana XSS via a query alias for the ElasticSearch datasource in...

6.1CVSS

5.6AI Score

0.001EPSS

2024-06-28 03:28 PM
1
osv
osv

HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault

HashiCorp Vault Improper Privilege Management in...

5.3CVSS

6.7AI Score

0.001EPSS

2024-06-28 03:28 PM
56
osv

4.3CVSS

6.8AI Score

0.0004EPSS

2024-06-28 03:28 PM
osv
osv

Authentik vulnerable to PKCE downgrade attack in goauthentik.io

Authentik vulnerable to PKCE downgrade attack in...

8.8CVSS

6.7AI Score

0.001EPSS

2024-06-28 03:28 PM
osv

6.1CVSS

6.4AI Score

0.0004EPSS

2024-06-28 03:28 PM
osv
osv

Grafana XSS via a column style in github.com/grafana/grafana

Grafana XSS via a column style in...

6.1CVSS

5.5AI Score

0.001EPSS

2024-06-28 03:28 PM
osv
osv

CubeFS leaks magic secret key when starting Blobstore access service in github.com/cubefs/cubefs

CubeFS leaks magic secret key when starting Blobstore access service in...

9.8CVSS

6.7AI Score

0.001EPSS

2024-06-28 03:28 PM
osv
osv

CubeFS timing attack can leak user passwords in github.com/cubefs/cubefs

CubeFS timing attack can leak user passwords in...

6.5CVSS

6.7AI Score

0.001EPSS

2024-06-28 03:28 PM
osv
osv

Minio unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation in github.com/minio/minio

Minio unsafe default: Access keys inherit admin of root user, allowing privilege escalation in...

8.8CVSS

7AI Score

0.002EPSS

2024-06-28 03:28 PM
osv
osv

Classic builder cache poisoning in github.com/docker/docker

Classic builder cache poisoning in...

7.8CVSS

6.6AI Score

0.001EPSS

2024-06-28 03:28 PM
osv
osv

Grafana information disclosure in github.com/grafana/grafana

Grafana information disclosure in...

5.5CVSS

6.3AI Score

0.001EPSS

2024-06-28 03:28 PM
osv
osv

Improper Authentication in HashiCorp Vault in github.com/hashicorp/vault

Improper Authentication in HashiCorp Vault in...

7.5CVSS

6.7AI Score

0.001EPSS

2024-06-28 03:28 PM
1
osv
osv

Hashicorp Vault may expose sensitive log information in github.com/hashicorp/vault

Hashicorp Vault may expose sensitive log information in...

6.5CVSS

6.4AI Score

0.001EPSS

2024-06-28 03:28 PM
1
osv
osv

Apache ServiceComb Service-Center Server-Side Request Forgery vulnerability in github.com/apache/servicecomb-service-center

Apache ServiceComb Service-Center Server-Side Request Forgery vulnerability in...

7.6CVSS

6.8AI Score

0.001EPSS

2024-06-28 03:28 PM
osv
osv

MongoDB Tools Improper Certificate Validation vulnerability in github.com/mongodb/mongo-tools

MongoDB Tools Improper Certificate Validation vulnerability in...

6.5CVSS

6.7AI Score

0.001EPSS

2024-06-28 03:28 PM
osv
osv

Rancher 'Audit Log' leaks sensitive information in github.com/rancher/rancher

Rancher 'Audit Log' leaks sensitive information in...

6.5AI Score

EPSS

2024-06-28 03:28 PM
osv

4.3CVSS

6.7AI Score

0.0004EPSS

2024-06-28 03:28 PM
osv

4.3CVSS

6.6AI Score

0.0004EPSS

2024-06-28 03:28 PM
osv

5.3CVSS

6.8AI Score

0.001EPSS

2024-06-28 03:28 PM
1
osv
osv

Buildkite Elastic CI for AWS time-of-check-time-of-use race condition vulnerability in github.com/buildkite/elastic-ci-stack-for-aws

Buildkite Elastic CI for AWS time-of-check-time-of-use race condition vulnerability in...

7CVSS

6.8AI Score

0.0004EPSS

2024-06-28 03:28 PM
1
osv
osv

Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault

Token leases could outlive their TTL in HashiCorp Vault in...

6.8CVSS

6.6AI Score

0.001EPSS

2024-06-28 03:28 PM
3
osv

4.1CVSS

6.8AI Score

0.0004EPSS

2024-06-28 03:28 PM
1
osv
osv

HashiCorp Vault Authentication bypass in github.com/hashicorp/vault

HashiCorp Vault Authentication bypass in...

8.2CVSS

6.7AI Score

0.004EPSS

2024-06-28 03:28 PM
1
osv
osv

Mattermost fails to properly restrict the access of files attached to posts in github.com/mattermost/mattermost-server

Mattermost fails to properly restrict the access of files attached to posts in...

3.1CVSS

6.6AI Score

0.0004EPSS

2024-06-28 03:28 PM
1
osv
osv

Enumeration of users in HashiCorp Vault in github.com/hashicorp/vault

Enumeration of users in HashiCorp Vault in...

5.3CVSS

6.7AI Score

0.001EPSS

2024-06-28 03:28 PM
56
osv
osv

SFTP is possible on the Proxy server for any user with SFTP access in github.com/gravitational/teleport

SFTP is possible on the Proxy server for any user with SFTP access in...

7.2AI Score

2024-06-28 03:28 PM
osv
osv

Moby Docker cp broken with debian containers in github.com/moby/moby

Moby Docker cp broken with debian containers in...

9.8CVSS

6.6AI Score

0.016EPSS

2024-06-28 03:28 PM
osv
osv

Grafana Cross-site Scripting (XSS) in github.com/grafana/grafana

Grafana Cross-site Scripting (XSS) in...

6.1CVSS

5.9AI Score

0.001EPSS

2024-06-28 03:28 PM
1
osv
osv

Denial of service in HashiCorp Consul in github.com/hashicorp/consul

Denial of service in HashiCorp Consul in...

7.5CVSS

6.6AI Score

0.002EPSS

2024-06-28 03:28 PM
osv
osv

Authenticated users can crash the CubeFS servers with maliciously crafted requests in github.com/cubefs/cubefs

Authenticated users can crash the CubeFS servers with maliciously crafted requests in...

6.5CVSS

6.7AI Score

0.0004EPSS

2024-06-28 03:28 PM
osv
osv

Mattermost vulnerable to denial of service via large number of emoji reactions in github.com/mattermost/mattermost-server

Mattermost vulnerable to denial of service via large number of emoji reactions in...

4.3CVSS

6.5AI Score

0.0005EPSS

2024-06-28 03:28 PM
osv

4.8CVSS

6.7AI Score

0.0004EPSS

2024-06-28 03:28 PM
osv
osv

The DES/3DES cipher was used as part of the TLS protocol by installation tools in github.com/karmada-io/karmada

The DES/3DES cipher was used as part of the TLS protocol by installation tools in...

7.1AI Score

2024-06-28 03:28 PM
osv
osv

Apache ServiceComb Service-Center Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/servicecomb-service-center

Apache ServiceComb Service-Center Exposure of Sensitive Information to an Unauthorized Actor vulnerability in...

7.5CVSS

6.6AI Score

0.001EPSS

2024-06-28 03:28 PM
1
osv
osv

Etcd pkg Insecure ciphers are allowed by default in go.etcd.io/etcd/client/pkg/v3

Etcd pkg Insecure ciphers are allowed by default in...

7.1AI Score

2024-06-28 03:28 PM
1
osv
osv

Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI

Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in...

8.8CVSS

6.5AI Score

0.001EPSS

2024-06-28 03:28 PM
1
osv
osv

Insecure random string generator used for sensitive data in github.com/cubefs/cubefs

Insecure random string generator used for sensitive data in...

9.8CVSS

6.7AI Score

0.001EPSS

2024-06-28 03:28 PM
1
osv
osv

chasquid HTTP Request/Response Smuggling vulnerability in github.com/albertito/chasquid in blitiri.com.ar/go/chasquid

chasquid HTTP Request/Response Smuggling vulnerability in github.com/albertito/chasquid in...

7.5CVSS

6.7AI Score

0.0005EPSS

2024-06-28 03:28 PM
1
osv

4.3CVSS

6.6AI Score

0.0004EPSS

2024-06-28 03:28 PM
1
osv

5.4CVSS

5.6AI Score

0.005EPSS

2024-06-28 03:28 PM
1
osv
osv

Evmos is missing precompile checks in github.com/evmos/evmos

Evmos is missing precompile checks in...

3.5CVSS

6.6AI Score

0.0004EPSS

2024-06-28 03:28 PM
1
osv
osv

Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpec in github.com/rancher/rancher

Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpec in...

6.9AI Score

EPSS

2024-06-28 03:28 PM
1
osv
osv

Rancher's External RoleTemplates can lead to privilege escalation in github.com/rancher/rancher

Rancher's External RoleTemplates can lead to privilege escalation in...

7.1AI Score

EPSS

2024-06-28 03:28 PM
1
osv
osv

Argo-cd authenticated users can enumerate clusters by name in github.com/argoproj/argo-cd

Argo-cd authenticated users can enumerate clusters by name in...

4.3CVSS

6.5AI Score

0.0004EPSS

2024-06-28 03:28 PM
1
Total number of security vulnerabilities2675408