Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Wish has SCP Path Traversal that allows arbitrary file read/write
CVE-2026-6437
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
go-git: Credential leak via cross-host redirect in smart HTTP transport
OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR
Dapr: Service Invocation path traversal ACL bypass
CVE-2026-5160
goldmark vulnerable to Cross-site Scripting (XSS)
CVE-2026-5807
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
CVE-2026-4525
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
CVE-2026-5052
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
CVE-2026-3605
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service
Istio: SSRF via RequestAuthentication jwksUri
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)
Kyverno: ServiceAccount token leaked to external servers via apiCall service URL
Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
CVE-2026-40611
ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
CVE-2026-40304
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records
CVE-2026-40303
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVE-2026-40302
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
CVE-2026-40173
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
Showing 1 - 20 of 1,000+ results