Filter
AND
-Infinity
0

Yocto ProjectInput Validation

First published (updated )

pip/torchCode Injection, Command Injection

First published (updated )

Spinnaker OrcaImproper Access Control in spinnaker

First published (updated )

Argo CDImproper access control allows admin privilege escalation in Argo CD

First published (updated )

Argo CDArgo CD will blindly trust JWT claims if anonymous access is enabled

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

go/github.com/argoproj/argo-cd/v2External URLs for Deployments can include javascript in argo-cd

First published (updated )

Linux Foundation Argo CDArgo CD's certificate verification is skipped for connections to OIDC providers

First published (updated )

Loopback Connector for PostgreSQLloopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filter

First published (updated )

Hyperledger BesuIncorrect Conversion between Numeric Types in Besu Ethereum Client

First published (updated )

go/d7y.io/dragonfly/v2Dragonfly2 vulnerable to hard coded cyptographic key

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

containerdImproper Preservation of Permissions in containerd

First published (updated )

DexOAuth authorization code exposure in Dex

First published (updated )

PipeCDInsecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, …

First published (updated )

Modular Open Smart NetworkAuthentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensit…

First published (updated )

Yocto ProjectInput Validation

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Argo CDJWT audience claim is not verified

First published (updated )

Argo CDArgo CD users with any cluster secret update access may update out-of-bounds cluster secrets

First published (updated )

Red Hat FedoraVersions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the…

EPSS
0.04%
First published (updated )

Yocto ProjectYocto Project Security Advisory - BitBake/Toaster

EPSS
0.04%
First published (updated )

Zowe API Mediation LayerHealth endpoint offers list of onboarded services to unauthenticated users

EPSS
0.05%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

npm/@backstage/plugin-scaffolder-backendInsecure sandbox in Backstage Scaffolder plugin

First published (updated )

TremorUse After Free

First published (updated )

runcOS Command Injection

First published (updated )

pip/tufTUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature…

First published (updated )

Argo CDCluster secret might leak in cluster details page in Argo CD

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

go/github.com/nats-io/nats-serverPath Traversal

First published (updated )

Linux Foundation Edge Virtualization EngineFreely Allocate Buffer on The Stack With Data From Socket

First published (updated )

Oracle UnifierPrototype Pollution

First published (updated )

Argo CDAll unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control …

First published (updated )

go/github.com/cubefs/cubefsInsecure random string generator used for sensitive data

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203