Where
-Infinity
0

go/github.com/argoproj/argo-cd/v3Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

Risk 61
Severity
8.7
First published (updated )

go/github.com/argoproj/argo-cd/v3Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations

Risk 38
Severity
6.5
First published (updated )

go/github.com/argoproj/argo-cd/v3ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

Risk 68
Severity
9.6
First published (updated )

argoproj Argo CDArgo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook

Risk 46
Severity
7.5
First published (updated )

argoproj Argo CDUnauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/argoproj/argo-cd/v2Argo CD' API server does not enforce project sourceNamespaces

Risk 34
Severity
6.3
EPSS
0.04%
First published (updated )

go/github.com/argoproj/argo-cd/v2Uncontrolled Resource Consumption vulnerability in ArgoCD's repo server

Risk 28
Severity
6.5
EPSS
0.04%
First published (updated )

go/github.com/argoproj/argo-cd/v2Argo CD vulnerable to Bypassing of Rate Limit and Brute Force Protection Using Cache Overflow

Risk 70
Severity
9.1
First published (updated )

go/github.com/argoproj/argo-cd/v2Argo CD Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

Risk 46
Severity
7.5
First published (updated )

go/github.com/argoproj/argo-cd/v2Argo CD vulnerable to Bypassing of Brute Force Protection via Application Crash and In-Memory Data Loss

Risk 90
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/argo-cdUsers with `create` but not `override` privileges can perform local sync in argo-cd

Risk 41
Severity
6.4
First published (updated )

go/github.com/argoproj/argo-cd/v2Cross-Site Request Forgery (CSRF) in github.com/argoproj/argo-cd

Risk 55
Severity
8.4
EPSS
0.05%
First published (updated )

go/github.com/argoproj/argo-cd/v2Path Traversal, Infoleak

Risk 46
Severity
7.7
First published (updated )

go/github.com/argoproj/argo-cdAs of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with acc…

Risk 82
Severity
8.8
First published (updated )

go/github.com/argoproj/argo-cdAs of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, accoun…

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

linuxfoundation Argo Continuous Delivery KubernetesAs of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication t…

Risk 43
Severity
7.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203