Database/Control plane, storage & DevOps
Control plane, storage and DevOps vulnerabilities
Cluster management, storage systems, CI/CD, and observability tooling: GitLab, Harbor, Grafana, MinIO, Ceph, and the operator-facing services that hold the keys to a GPU fleet.
699 entries202 critical82 known exploitedFilter and search this layer
2026
Linux crypto driver for Marvell OCTEON TX: The scatter-gather cleanup path in the Marvell OCTEON TX crypto driver usesCriticalAug 15, 2026- Linux VXLAN driver (neighbour hardware address read in route_shortcircuit): TENANT ISOLATION: `route_shortcircuit()`CriticalAug 15, 2026
- Linux VXLAN driver (transmit-path header pulls): TENANT ISOLATION: `vxlan_xmit()`, `arp_reduce()`CriticalAug 15, 2026
Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table): TENANT ISOLATION: the LiquidIO PF caches VFCriticalAug 15, 2026
Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler): TENANT ISOLATION: the OCTEON CN10K admin-functionHighAug 15, 2026- Linux octeontx2-af (VF clobbering shared CGX PKIND state): TENANT ISOLATION: PF and VF NIX logical functions that shareHighAug 15, 2026
- Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): TENANT ISOLATION: a VF setting its receive mode causesHighAug 15, 2026
- Linux perf/x86/amd/core - Branch Sampling enabled from the SVM reload path: Branch Sampling and Last Branch RecordUnscoredAug 15, 2026
IBM Storage Scale GUI (hardcoded inter-node token): A hardcoded token in the Storage Scale GUI source, usedHighAug 13, 2026- Linux VXLAN driver (CAP_NET_ADMIN check on changelink across netns): TENANT ISOLATION: a VXLAN tunnel's `changelink()`HighAug 12, 2026
- open-iscsi iscsiuio (DHCPv6 handling): Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handlingMediumAug 12, 2026
Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+): Three heap-basedCriticalAug 11, 2026- Linux iommu/amd - IRQ-unsafe locking in guest domain allocation: An IRQ-unsafe lock taken during AMD IOMMU guest domainUnscoredAug 10, 2026
N-able N-central: Incomplete patch for CVE-2026-18556HighAug 2, 2026
N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverHighAug 1, 2026- open-iscsi / open-isns - iscsiuio control socket authorization and iSNS record handling: Three related defectsHighJul 29, 2026
- JetBrains TeamCity: Deserialization in the agent polling protocolCriticalJul 27, 2026
Progress Kemp LoadMaster Multi Tenant: TENANT ISOLATION: the Multi Tenant product line's REST API doesn't check whetherHighJul 27, 2026- Linux crypto/ccp - SNP initialization on ioctl(SNP_COMMIT): The ccp driver initialised SNP from the SNP_COMMIT ioctlUnscoredJul 25, 2026
- Linux x86/mm - broadcast TLB flush with PCID disabled: Booting with nopcid clears the PCID feature but broadcast TLBUnscoredJul 24, 2026
- Linux MACsec (replay protection at XPN lower-PN wrap): TENANT ISOLATION: MACsec replay protection failsHighJul 19, 2026
- Linux iommu/amd - devid bounds check in __rlookup_amd_iommu(): MULTI-TENANT ISOLATION: The AMD IOMMU driver looked upMediumJun 26, 2026
ATEN Unizon fleet management platform: TENANT ISOLATION: Unizon is ATEN's centralized manager for its KVM and PDUHighJun 24, 2026- Linux amd-pstate - memory leak in amd_pstate_epp_cpu_init(): On failure to set the energy-performance preferenceMediumJun 24, 2026
- Backpropagate (single-GPU LLM fine-tuning library) - Reflex web UI: The optional web UI exposes a training controlCriticalJun 17, 2026
Ivanti Sentry: OS command injectionCriticalJun 9, 2026- Fortinet FortiSandbox: OS command injectionCriticalJun 9, 2026
lldpd (802.1Q VLAN tag stripping in lldpd_decode): lldpd strips 802.1Q VLAN tags by memmove-ing the frame payload fourMediumJun 9, 2026
Schneider Electric Data Center Expert - SOAP service endpoints: XML external entity processing on DCE SOAP endpointsMediumJun 9, 2026
Progress LoadMaster (ADC): OS command injection in the APICriticalJun 4, 2026
CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching): Stack-based buffer overflow in BIRD's AS_PATH maskMediumJun 2, 2026- Palo Alto PAN-OS: GlobalProtect portal/gateway auth bypassCriticalMay 13, 2026
Ivanti Endpoint Manager Mobile: Improper input validationHighMay 7, 2026- Palo Alto PAN-OS: Buffer overflow in the User-ID Captive PortalCriticalMay 6, 2026
- Linux iommu/vt-d (dev-IOTLB flush in scalable mode): TENANT ISOLATION: the scalable-mode half of the device-IOTLBMediumMay 6, 2026
- Linux iommu/vt-d (dev-IOTLB flush for passed-through PCIe devices): TENANT ISOLATION: the Intel IOMMU driver skipsMediumMay 6, 2026
- Linux EDAC/mc - error path ordering in edac_mc_alloc(): When a private-data allocation fails in edac_mc_alloc()MediumApr 27, 2026
- Fortinet FortiSandbox: OS command injection via crafted HTTP requestsCriticalApr 14, 2026
- Apache Tomcat: Missing encryption of sensitive data introduced by the CVE-2026-29146 fixHighApr 9, 2026
- Apache ActiveMQ: Improper input validation and code injection in the brokerHighApr 7, 2026
- Fortinet FortiClient EMS: Improper access controlCriticalApr 4, 2026
- Linux perf/x86 - event pointer setup ordering in x86_pmu_enable(): A NULL pointer dereference in the x86 PMU enableMediumApr 3, 2026
- Citrix NetScaler ADC/Gateway: Insufficient input validation as SAML IdPCriticalMar 23, 2026
Ivanti Endpoint Manager (EPM): Auth bypass via alternate pathHighFeb 10, 2026- Fortinet FortiClient EMS: Unauthenticated SQL injectionCriticalFeb 6, 2026
Ivanti Endpoint Manager Mobile: Code injectionCriticalJan 29, 2026
Ivanti Endpoint Manager Mobile: Code injectionCriticalJan 29, 2026- Fortinet (FortiOS/FortiManager/FortiProxy): Auth bypass via alternate path using a FortiCloud account and a registeredCriticalJan 27, 2026
- Linux NFS server (nfsd, NFSv4.0 LOCK replay cache): A denied NFSv4.0 LOCK whose conflicting owner string is largeCritical2026
- rclone (rcd remote control server): An unauthenticated request to the rclone remote-control server instantiates aCritical2026
- Proxmox VE (libpve-storage-perl XXE): XML external entity injection in the Proxmox storage library, reachableCritical2026
- Linux NFS server (nfsd, SECINFO_NO_NAME decode): A truncated SECINFO_NO_NAME operation leaves sin_exp uninitialized andCritical2026
- VMware vCenter (VMware Directory Service authentication bypass): An unauthenticated attacker with network accessCritical2026
- VMware vCenter (Syslog server directory traversal to RCE): Directory traversal in the vCenter syslog server lettingCritical2026
- Linux SUNRPC (xdr_buf_to_bvec, nfsd write path): xdr_buf_to_bvec stores a bio_vec before checking the slot is in rangeCritical2026
- Assisted Migration Agent (hardcoded insecure TLS to vCenter): The agent hardcodes insecure TLS when talking to vCenterCritical2026
- MinIO (OIDC authentication): MULTI-TENANT ISOLATION: JWT algorithm confusion in the OIDC login path lets an attackerCritical2026
- rclone (rc API, options/set): options/set is exposed pre-authentication and can rewrite the running instance's authCritical2026
- rclone (rc API, operations/fsinfo): operations/fsinfo is reachable without authentication and accepts anCritical2026
- Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to ProxmoxCritical2026
- BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gateways: A runCritical2026
Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole): MULTI-TENANT ISOLATION: TheHigh2026- NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID): MULTI-TENANT ISOLATION: an attacker who alreadyHigh2026
- Supermicro SMASH service (X14DBG-DAP, X14DBI): An attacker with any authorised BMC login escalates through the SMASHHigh2026
- MinIO (S3 API, Snowball auto-extract): MULTI-TENANT ISOLATION: the Snowball auto-extract path skips signatureHigh2026
- MinIO (S3 API, unsigned-trailer uploads): MULTI-TENANT ISOLATION: the signature on a query-string-credentialHigh2026
- rclone (serve restic --private-repos): MULTI-TENANT ISOLATION: --private-repos is meant to confine each authenticatedHigh2026
- SkyPilot (API server, service account role update authorization): MULTI-TENANT ISOLATION: SkyPilot never checks whetherHigh2026
- Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64): An out-of-boundsHigh2026
- Pure Storage FlashArray Purity (data path information exposure): Insufficient filtering on certain data paths exposesHigh2026
- Pure Storage FlashArray Purity (management interface privilege bypass): An authenticated low-privileged user reachesHigh2026
- rclone (serve restic): MULTI-TENANT ISOLATION: path validation in serve restic is incomplete, so an authenticatedHigh2026
- Pure Storage FlashBlade logging: Sensitive material ends up in FlashBlade logs under certain conditions, and the scoredHigh2026
- Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodesHigh2026
- Cisco Intersight Device Connector for Nutanix Prism Central: The device connector exposes an unauthenticated APIHigh2026
- VMware Aria Operations (command injection during assisted migration): An unauthenticated attacker injects commandsHigh2026
- MUNGE (munged credential daemon): MULTI-TENANT ISOLATION: This is the root of trust under Slurm. A crafted message withHigh2026
- Dell OpenManage Server Administrator (improper authentication): An unauthenticated remote attacker gets unauthorizedHigh2026
- Automated Logic WebCTRL / i-Vu server and controllers, BACnet transport trust: This is the vendor formally concedingHigh2026
- rclone (local backend, --links): When rclone copies from an untrusted remote with --links, it recreates symlinksHigh2026
- MinIO (server-side encryption / replication): An authenticated tenant can inject SSE metadata through replicationHigh2026
- MinIO (S3 Select): A crafted S3 Select CSV query makes MinIO allocate memory without bound until the process isHigh2026
- Determined AI (master API, generic task kill/pause/unpause handlers): MULTI-TENANT ISOLATION: The generic task killHigh2026
- Volcano (admission webhook server, unbounded HTTP request body): MULTI-TENANT ISOLATION: The Volcano webhook serverMedium2026
- rclone (S3 backend, redirect sanitization): When rclone's S3 backend follows a redirect it strips some sensitiveMedium2026
- Dell OpenManage Server Administrator (relative path traversal): A low-privileged remote attacker reads arbitrary filesMedium2026
- rclone (serve s3): Path traversal in rclone's S3 gateway lets a caller read and overwrite files above the served root.Medium2026
IBM Storage Scale management GUI (deploy and upgrade logging): The Storage Scale admin password is written in the clearMedium2026
DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls): Stack corruption inside the firmwareMedium2026
DMTF libspdm responder handling of GET_MEASUREMENT_EXTENSION_LOG: A requester reads memory it was never authorisedMedium2026- rclone (rc server, /debug/pprof handler): The pprof debug handler is mounted as its own route on the rcloneMedium2026
- NetApp ONTAP S3 NAS bucket directory listing: MULTI-TENANT ISOLATION: an authenticated S3 user lists the contents ofMedium2026
- SkyPilot (sky/users/server.py, user ID derivation from username): User IDs are derived with a weak hash of theLow2026
- QCT (Quanta Cloud Technology) server security centre: QCT firmware is unmeasurable from public data despiteUnscored2026
- Supermicro's public security advisory portal itself: An operator cannot programmatically track Supermicro firmwareUnscored2026
- Tyan / MiTAC Computing PSIRT: For Tyan, this vendor's firmware is unmeasurable from public dataUnscored2026
DMTF SPDM specification DSP0274 1.4 (FINISH transcript definition): A specification-level defect rather thanUnscored2026
DMTF libspdm (GET_MEASUREMENT_EXTENSION_LOG offset/length wrap): Wrapping addition of the Offset and Length fieldsUnscored2026- Linux Safe RET SRSO mitigation on AMD Zen 1-Zen 4 - interrupt-induced weakening: MULTI-TENANT ISOLATION: An attackerUnscored2026
DMTF libspdm (cryptlib_mbedtls CSR generation, stack overflow): An over-long Common Name in a GET_CSR request writesUnscored2026- AMD - REP-string execution unit scheduler contention side channel: MULTI-TENANT ISOLATION: A newer variant of the SQUIPUnscored2026
Das U-Boot (FIT image signature verification): Binarly disclosed a cluster of flaws in U-Boot's FIT image handlingUnscored2026
WEKA Data Platform and VAST Data (published-advisory coverage): Neither WEKA nor VAST DataUnscored2026- BACnet / BACnet IP as a protocol (facility control plane): BACnet has no authentication, no integrity protection and noUnscored2026
NVMe-oF fabric authentication as deployed - host NQN allowlisting on Linux nvmet, SPDK and most storage appliancesUnscored2026- Landlord-owned facility control network in a leased colo or wholesale hall (governance gap): Almost every neocloudUnscored2026
- SES (SCSI Enclosure Services) enclosure management on shared SAS JBODs and expanders: SES is how a host controlsUnscored2026
- Modbus TCP as an unauthenticated control channel on facility gear: Modbus TCP has no authentication, no authorizationUnscored2026
- Wiegand reader-to-controller wiring and legacy 125 kHz proximity / MIFARE Classic credentials: Two structuralUnscored2026
- HTCondor (Access Point daemons, condor identity): MULTI-TENANT ISOLATION: A user with WRITE authorization on an AccessUnscored2026
Kubeflow Pipelines (frontend server, /_proxy/ route in proxy-middleware.ts): MULTI-TENANT ISOLATION: The KubeflowUnscored2026
2025
- Arm Neoverse N1 / N2 / V1 / V2 / V3 / V3AE, Cortex-A76/A77/A78/A710, Cortex-X1-X925, C1-Ultra/PremiumCriticalJun 9, 2026
- AMD IOMMU register interface - ASP coherency: Improper access control on the IOMMU register interface lets a privilegedMediumJun 9, 2026
- AMD AGESA bootloader - DDR5 PMIC default configuration: The AGESA bootloader leaves DDR5 memory modules in an insecureMediumMay 15, 2026
- AMD NBIO register lock bits - System Management Network access: MULTI-TENANT ISOLATION: NBIO registers that shouldHighMay 13, 2026
- AMD NBIO register lock bits - MMIO routing configuration: MULTI-TENANT ISOLATION: The sibling of the SMN issueMediumMay 13, 2026
Lantronix EDS5000 serial-to-Ethernet device server: Root command execution on the device serverCriticalMar 11, 2026
Lantronix EDS3000PS serial-to-Ethernet device server: Full bypass of the management-page loginCriticalMar 11, 2026- AMD Graphics Driver - out-of-bounds write: MULTI-TENANT ISOLATION: Improper input validation lets a local attackerMediumFeb 11, 2026
- AMD - overlap between segmented reverse map table (RMP) and SMM memory: MULTI-TENANT ISOLATION: Improper handlingMediumFeb 10, 2026
- Linux perf/x86/amd - general protection fault from a NULL event on enable: A subtle race lets cpucUnscoredJan 13, 2026
- MongoDB Server: Mismatched Zlib compressed header lengthsHighDec 19, 2025
- AMD Zen 5 RDSEED (16-bit and 32-bit variants): MULTI-TENANT ISOLATION: On Zen 5, the 16-bit and 32-bit forms of RDSEEDHighDec 16, 2025
Sunbird Power IQ 9.2.0 API: Error-based SQL injection through an outdated API endpoint with missing input validationLowDec 15, 2025- AMD CPUs - attacker influence over RDSEED entropy: MULTI-TENANT ISOLATION: A local attacker can influence the valuesHighNov 21, 2025
- Go crypto/x509 (Tailscale, Go infra): Name-constraint checking scales non-linearly with certificate sizeHighOct 29, 2025
- F5 BIG-IP (APM access policy): Specific malicious traffic against a virtual server with a BIG-IP APM access policyCriticalOct 15, 2025
- F5 BIG-IP (iHealth command / tmsh restricted shell): An authenticated attacker with at least a resource-administratorHighOct 15, 2025
- Linux iommu/amd - race while increasing host page table level: MULTI-TENANT ISOLATION: The AMD IOMMU host page tableHighOct 9, 2025
- Redis: "RediShell" - authenticated user crafts a Lua script to trigger a use-after-freeCriticalOct 3, 2025
SPDK (Storage Performance Development Kit) 25.05 - NVMe-oF target, lib/nvmf: TENANT ISOLATION: A buffer overflowMediumOct 1, 2025
SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12): Rowhammer bit flips on DDR5, which had been assumed outHighSep 15, 2025- Citrix NetScaler: Memory overflowCriticalAug 26, 2025
- Linux x86/CPU/AMD - INVLPGB on Zen 2 (Cyan Skillfish): Using broadcast TLB invalidation (INVLPGB) on affected Zen 2MediumAug 16, 2025
N-able N-central: Improper input validationHighAug 14, 2025
N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM serverHighAug 14, 2025- Intel oneAPI toolkit and component installers: An uncontrolled library search path: the component loads a sharedMediumAug 12, 2025
- Intel oneAPI DPC++/C++ compiler installer: The compiler installer sets permissions that let a local user modifyMediumAug 12, 2025
- Intel oneAPI DPC++/C++ compiler: An uncontrolled library search path: the component loads a shared library by nameMediumAug 12, 2025
- HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault hostCriticalAug 1, 2025
OAuth2-Proxy: skip_auth_routes route matching flawCriticalJul 30, 2025
Lantronix Provisioning Manager: Provisioning Manager reads configuration files supplied by the network devicesHighJul 22, 2025- Fortinet FortiWeb: Unauthenticated SQL injectionCriticalJul 17, 2025
- Jenkins (Git Parameter plugin): Git parameter value is not validated against the offered choicesHighJul 9, 2025
Marvell QConvergeConsole (QLogic Fibre Channel / FC-NVMe / CNA HBA management web console), 5.5.0.78 and earlierCriticalJul 7, 2025- Redis: Authenticated user triggers a stack/heap out-of-bounds write in hyperloglog opsHighJul 7, 2025
- Citrix NetScaler ADC / Gateway (configured as VPN Gateway, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server): A memoryCriticalJun 25, 2025
- Kibana: Open redirect leading to SSRF via a specially crafted URLMediumJun 25, 2025
- Veeam Backup & Replication: Authenticated domain user achieves remote code execution on the Backup ServerHighJun 19, 2025
Teleport: Remote authentication bypass in Teleport Community Edition (<=17.5.1)CriticalJun 17, 2025- Citrix NetScaler ADC/Gateway: "CitrixBleed 2" - insufficient input validationHighJun 17, 2025
- Apache Kafka (client): SASL/OAUTHBEARER endpoint URLs accept file://HighJun 10, 2025
- AMD Versal Adaptive SoC - PLM runtime services address validation: MULTI-TENANT ISOLATION: The Platform LoaderMediumJun 10, 2025
- Cisco Nexus Dashboard Fabric Controller (SSH host key validation): NDFC does not validate the SSH host keysHighJun 4, 2025
- Grafana: Client path traversal + open redirectHighMay 22, 2025
- HashiCorp Nomad Enterprise: Jobs using the policy-override option bypass mandatory Sentinel policiesHighMay 13, 2025
- Intel E810 NVM Update Utility: Insecure inherited permissions in the NVM update utilityMediumMay 13, 2025
- OpenVINO Model Server: An unauthenticated request can drive OpenVINO Model Server into unbounded resource consumptionMediumMay 13, 2025
IBM Storage Scale (command input neutralization): An authenticated user can execute privileged commands due to improperHighMay 10, 2025
Arista CloudVision (Zero Touch Provisioning): Zero Touch Provisioning can be abused to obtain admin privilegesCriticalMay 8, 2025- HashiCorp Vault: KV v2 leaks sensitive payload content into server and audit logs on malformed requestsMediumMay 2, 2025
- Commvault Web Server: Remote authenticated attacker creates and executes webshellsHighApr 25, 2025
ConnectWise ScreenConnect: ViewState code injectionHighApr 25, 2025- Commvault Command Center: Unauthenticated ZIP upload + path traversalCriticalApr 22, 2025
- Linux cpufreq/amd-pstate - missing NULL check in amd_pstate_update: amd_pstate_update() dereferences the cpufreq policyMediumApr 16, 2025
Ivanti Connect Secure/ZTA: Stack-based buffer overflowCriticalApr 3, 2025- OpenVPN: Corrupting and replaying early-handshake packets against a tls-crypt-v2 serverHighApr 2, 2025
- Veeam Backup & Replication: Remote code execution reachable by any domain user on a domain-joined backup serverHighMar 20, 2025
- GitLab (ruby-saml): ReXML/Nokogiri parser differentialCriticalMar 12, 2025
- Linux cpufreq/amd-pstate - cpufreq_policy reference counting: amd_pstate_update_limits() takes a cpufreq_policyMediumMar 7, 2025
- Cisco Nexus 3000/9000 (health monitoring diagnostics): FABRIC DOS: the health monitoring diagnostics subsystem on NexusHighFeb 26, 2025
- PostgreSQL (libpq): Improper quoting in PQescape*HighFeb 13, 2025
- Palo Alto PAN-OS: Management web interface auth bypass invoking PHP scriptsCriticalFeb 12, 2025
- Argo CD: Secret values exposed in error messages and the diff view when an invalid Secret is syncedMediumJan 30, 2025
- Linux platform/x86/amd/pmc - IRQ1 wakeup disabled unconditionally: The AMD PMC driver disabled IRQ1 wakeup in casesMediumJan 19, 2025
Ivanti Connect Secure: Stack-based buffer overflowCriticalJan 8, 2025- Deep Sea Electronics DSE855 generator communications gateway v1.1.0-v1.1.26 (realtime.cgi): Incorrect access controlCritical2025
HPE OneView (unauthenticated remote code execution): Unauthenticated remote code execution on OneView with scope changeCritical2025
HPE StoreOnce (command injection RCE): Unauthenticated remote code execution on the backup applianceCritical2025
HPE StoreOnce (server-side request forgery): SSRF from the backup appliance, letting an unauthenticated attacker pivotCritical2025
HPE StoreOnce (command injection RCE): Second unauthenticated command-injection RCE path on StoreOnceCritical2025
HPE StoreOnce (authentication bypass): Unauthenticated attacker bypasses authentication on StoreOnce entirely, gainingCritical2025
HPE StoreOnce (directory traversal information disclosure): Unauthenticated directory traversal disclosing filesCritical2025
HPE StoreOnce (command injection RCE): Third unauthenticated command-injection RCE path on StoreOnceCritical2025- HPE Insight Remote Support (remote code execution): Unauthenticated remote code execution on the Insight RS serverCritical2025
- Linux NFS server (nfsd, nfsd4_spo_must_allow): nfsd4_spo_must_allow examines NFSv4 compound state without firstCritical2025
- Linux NFS server (nfsd, nfsd_set_fh_dentry): A refcount leak in the pseudo-root filehandle path lets a client drive theCritical2025
Vertiv (stack-based buffer overflow, code execution): A stack overflow gives an attacker code execution on the VertivCritical2025
Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cards: Authentication bypass plusCritical2025- Johnson Controls Metasys Application and Data Server (ADS) deployed with SQL Express: Command injection on the MetasysCritical2025
- Dell CloudLink (restricted shell breakout): A privileged user breaks out of the restricted shell into a full commandCritical2025
- Dell CloudLink (CLI escape): A privileged user with a known password escapes the CLI and takes control of the CloudLinkCritical2025
- Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone Controller: Malformed BACnetHigh2025
- Dell OpenManage Network Integration (RADIUS auth bypass): An attacker on the local network forges a valid RADIUS AcceptHigh2025
- VMware vCenter Server (authenticated command execution via alarms): A user with permission to create or modify alarmsHigh2025
- MinIO (S3 API, unsigned-trailer uploads): MULTI-TENANT ISOLATION: signature validation on unsigned-trailer uploads isHigh2025
HPE OneView for VMware vCenter (vertical privilege escalation): A read-only user performs administrative actionsHigh2025- VMware Aria Operations for Logs (credential disclosure): A View Only Admin reads the credentials of other VMwareHigh2025
- VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissionsHigh2025
- Dell CloudLink (command injection): Command injection giving a privileged user full control of the CloudLink systemHigh2025
- Dell CloudLink (console command injection): Command injection from the console giving shell accessHigh2025
- Pure Storage FlashBlade authentication input validation: The FlashBlade equivalent of the FlashArray pre-authenticationHigh2025
- Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack bufferHigh2025
- VMware Aria Automation (DOM-based XSS, token theft): A crafted URL steals the access token of a logged-in AriaHigh2025
- OpenShift Hive / MCE / ACM (vCenter credential exposure): vCenter credentials are written into the ClusterProvisionHigh2025
HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUIHigh2025- HTCondor (IDToken authorization restrictions): MULTI-TENANT ISOLATION: The per-token authorization restrictionsHigh2025
- MinIO (service accounts / STS session policies): MULTI-TENANT ISOLATION: the session policy attached to a serviceHigh2025
- Linux NFS server (nfsd, NFSv4 file creation ACL): MULTI-TENANT ISOLATION: when a client sets an ACL during NFSv4 fileHigh2025
- Tridium Niagara Framework and Niagara Enterprise Security (before 4.10.11 / 4.14.2 / 4.15.1): A chain, not a singleHigh2025
- HPE Insight Remote Support (unauthenticated denial of service): An unauthenticated attacker takes Insight RS downHigh2025
- HPE Insight Remote Support (path traversal): Unauthenticated path traversal disclosing files from the IRS serverHigh2025
- Volcano (scheduler, Elastic service and extender plugin response handling): MULTI-TENANT ISOLATION: The scheduler readsHigh2025
- Motherboards from ASRock and its subsidiaries ASRockRack and ASRockInd built on Intel 500-series chipsetsMedium2025
- Dell CloudLink (privilege escalation to database): A privileged user escalates laterally or reads the CloudLinkMedium2025
- Dell CloudLink (risky cryptographic primitive): Use of a cryptographic primitive with a risky implementationMedium2025
IBM Storage Scale SMB protocol stack (inherited ACL handling): MULTI-TENANT ISOLATION: files created or modified overMedium2025- CephFS (ceph-fuse client): MULTI-TENANT ISOLATION: a tenant with an ordinary unprivileged UID on a node that has aMedium2025
- MinIO (SFTP gateway): MULTI-TENANT ISOLATION: the SFTP frontend trusts an SSH public key it should not, letting anMedium2025
Slurm (slurmdbd accounting, Coordinator role): MULTI-TENANT ISOLATION: A Coordinator - the delegated role a site givesMedium2025- HTCondor (condor_schedd / Access Point): MULTI-TENANT ISOLATION: A user plants a specially crafted job that liesMedium2025
- AMD Zen 3 / Zen 4 - new exploitation method for SRSO (CVE-2023-20569): MULTI-TENANT ISOLATION: Google's security teamUnscored2025
- AMD confidential computing - DDR5 memory bus interposition against TEEs: MULTI-TENANT ISOLATION: Compromising trustedUnscored2025
2024
- AMD Radeon RGB tool - signature verification on files in the installation directory: The Radeon RGB tool doesHighMay 15, 2026
- AMD PCIe link handling (memory buffer bounds): A guest VM can drive the PCIe link into an out-of-bounds conditionMediumFeb 13, 2026
- AMD Graphics Driver - crafted pointer leading to arbitrary code execution: MULTI-TENANT ISOLATION: Improper inputHighFeb 11, 2026
- AMD Graphics Driver - integer overflow bypassing size checks: An integer overflow in the AMD graphics driver letsMediumFeb 11, 2026
APC Network Management Card 4 (NMC4): An unauthenticated attacker can manipulate URL parameters to walk out of the webHighDec 11, 2025- AMD Graphics Driver - crafted pointer leading to arbitrary writes: MULTI-TENANT ISOLATION: A specially crafted pointerHighSep 6, 2025
- AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014): MULTI-TENANT ISOLATION: The BadRAM SPD-aliasingHighSep 6, 2025
- AMD Optimizing CPU Libraries (AOCL) - installation directory permissions: AOCL installs with permissive directoryHighMay 13, 2025
- Intel Data Center GPU Flex Series - Windows driver: Improper buffer restrictions in the Flex Series Windows driver letHighMay 13, 2025
- AMD Optimizing CPU Libraries (AOCL) - DLL hijacking: A DLL search-order hijack in AOCL lets an attacker getHighMay 13, 2025
- Intel Data Center GPU Flex Series - Windows driver: A further improper access control in the Flex Series Windows driverHighMay 13, 2025
- Intel oneAPI Level Zero software: An uncontrolled search path in Level Zero lets an authenticated local user get codeMediumMay 13, 2025
- Intel oneAPI DPC++/C++ compiler: An uncontrolled library search path: the component loads a shared library by nameMediumMay 13, 2025
- Intel Data Center GPU Flex Series - Windows driver software: Improper access control in the Flex Series Windows driverMediumMay 13, 2025
Arista CloudVision Portal (on-premise): An authenticated CloudVision user can take actions on managed EOS devices wellCriticalMay 8, 2025
NAKIVO Backup & Replication: Unauthenticated absolute path traversal via getImageByPathHighMar 4, 2025- Fluent Bit: Prometheus Remote Write input crashes on a Content-Length: 0 packetHighFeb 18, 2025
- Fluent Bit: OpenTelemetry input plugin crashes on a Content-Length: 0 packetHighFeb 18, 2025
- AmdCpmDisplayFeatureSMM - SMM callout (AMD-SB-7027): MULTI-TENANT ISOLATION: An SMM calloutHighFeb 11, 2025
- AmdPlatformRasSspSmm - SMM callout (AMD-SB-7028): MULTI-TENANT ISOLATION: An SMM callout in the platform RAS SMM driverHighFeb 11, 2025
- AmdPspP2CmboxV2 - SMM input validation (AMD-SB-7027): MULTI-TENANT ISOLATION: Insufficient input validationHighFeb 11, 2025
CyberPower PowerPanel Business 4.11.0 - Service Watchdog on TCP/2003: An unauthenticated attacker can repeatedlyHighJan 15, 2025- Fortinet FortiOS/FortiProxy: Auth bypass via crafted Node.js websocket requestsCriticalJan 14, 2025
- Redis: Malformed ACL selector triggers a server panicMediumJan 6, 2025
IBM Storage Scale GUI (local privilege escalation): A local privilege escalation in the Storage Scale GUI availableHighDec 14, 2024- Arm Neoverse V1 / V2 / V3 / V3AE / N2 and Cortex-A77/A78/A710/X1-X925 cores with Hardware Page Aggregation enabledCriticalDec 10, 2024
Digi ConnectPort LTS (before 1.4.12): An attacker who can reach the ConnectPort LTS's file-upload featureHighDec 9, 2024
Zabbix: SQL injection in CUser::addRelatedObjects reachable by ANY non-admin account with API accessCriticalNov 27, 2024- Keycloak: Regex complexity in SearchQueryUtilsMediumNov 25, 2024
- Apache Kafka (client): ConfigProvider plugins let an untrusted app read files/env of the Kafka client hostMediumNov 19, 2024
- Palo Alto PAN-OS: Management web interface authentication bypassCriticalNov 18, 2024
- Palo Alto PAN-OS: Admin with mgmt-interface access performs firewall actions as rootHighNov 18, 2024
- PostgreSQL: PL/Perl lets an unprivileged DB user change process env vars (e.g. PATH)HighNov 14, 2024
- Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural CompressorHighNov 13, 2024
- Intel Neural Compressor: Unauthenticated input-validation failure leading to escalation of privilege in NeuralHighNov 13, 2024
- Intel Neural Compressor (SQL injection, second instance): A second SQL-injection path in Neural Compressor reachableHighNov 13, 2024
- Intel Distribution of OpenVINO Model Server: An unauthenticated user can reach an input-validation flaw in OpenVINOMediumNov 13, 2024
- Intel Neural Compressor: Input-validation failure reachable by an authenticated user, ending in privilege escalationMediumNov 13, 2024
- Prometheus / Thanos (golang-jwt): Unclear ParseWithClaims error behaviorLowNov 4, 2024
- HashiCorp Consul: Missing Content-Type header lets user input be reinterpretedMediumOct 30, 2024
- Fortinet FortiManager: "FortiJump" - missing authentication in fgfmdCriticalOct 23, 2024
- Linux cpufreq/amd-pstate - unchecked cpufreq_cpu_get() return value: cpufreq_cpu_get() can return NULL and amd-pstateMediumOct 21, 2024
- Grafana: SQL Expressions passes user input to duckdb unsanitizedCriticalOct 18, 2024
Schneider Electric Data Center Expert - upgrade bundle signature verification: Improper cryptographic signatureHighOct 11, 2024- GitHub Enterprise Server: Improper signature verificationCriticalOct 10, 2024
- HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policyHighOct 10, 2024
- Cisco Nexus Dashboard Fabric Controller (REST API / web UI): A low-privileged NDFC userCriticalOct 2, 2024
- Keycloak: SAML signature scope determined by position, not ReferenceHighSep 19, 2024
- Linux HID/amd_sfh - driver_data freed after HID device destruction: A use-after-free in the AMD Sensor Fusion Hub HIDHighSep 18, 2024
- GitLab (ruby-saml): Ruby-SAML does not properly verify the SAML Response signatureCriticalSep 10, 2024
- Veeam Backup & Replication: Deserialization of untrusted dataCriticalSep 7, 2024
Progress Kemp LoadMaster (including Multi-Tenancy edition): TENANT ISOLATION: a request handler fails to validateCriticalSep 5, 2024
Infineon cryptographic library (ECDSA) in security microcontrollers: Electromagnetic side channel in Infineon's ECDSAMediumSep 3, 2024- GitHub Enterprise Server: XML signature wrapping with publicly exposed federation metadataCriticalAug 20, 2024
- Intel oneAPI compiler: An uncontrolled library search path: the component loads a shared library by nameMediumAug 14, 2024
- Intel Data Center GPU Max Series 1100 / 1550: A second improper conditions check in the Max Series allowingMediumAug 14, 2024
- Kibana: Prototype pollution via ML/Alerting connectors + write access to internal ML indicesCriticalAug 13, 2024
- PostgreSQL: TOCTOU race in pg_dumpHighAug 8, 2024
- Jenkins: Agent processes can read arbitrary controller files via ClassLoaderProxy#fetchJarHighAug 7, 2024
- Gitea: Stored cross-site scripting in Gitea 1.22.0CriticalAug 6, 2024
- Elasticsearch: elasticsearch-certutil --csr writes the private key to disk unencrypted despite --passMediumJul 31, 2024
- Linux cpufreq/amd-pstate - memory leak on CPU EPP exit: The amd-pstate driver leaks its per-CPU allocation when a CPU'sMediumJul 12, 2024
- GitLab: Attacker can trigger a CI pipeline as another userCriticalJul 11, 2024
OpenVPN (tap-windows6): Unchecked write sizeCriticalJul 8, 2024- OpenVPN: Stack overflow in the interactive serviceHighJul 8, 2024
- OpenVPN: The interactive service pipe is reachable remotelyHighJul 8, 2024
A10 Thunder ADC (CsrRequestView): An authenticated attacker can inject a system-call payload through the CsrRequestViewHighJun 6, 2024- OpenTelemetry Collector: Unsafe decompressionHighJun 5, 2024
- Veeam Backup Enterprise Manager: Unauthenticated users can log in as any user to the Enterprise Manager web interfaceCriticalMay 22, 2024
- Fluent Bit: "Linguistic Lumberjack" - memory corruption parsing trace requests in the embedded HTTP serverCriticalMay 20, 2024
- GitHub Enterprise Server: Forged SAML response with encrypted assertions enabledCriticalMay 20, 2024
Zabbix: Unsanitized clientip in the audit logCriticalMay 17, 2024- Intel Neural Compressor: An unauthenticated user can reach an input-validation failure in Neural CompressorCriticalMay 16, 2024
- Sonatype Nexus Repository 3: Unauthenticated path traversalHighMay 16, 2024
- Intel Neural Compressor (TOCTOU): A time-of-check/time-of-use race in Neural Compressor lets an authenticated localMediumMay 16, 2024
CyberPower PowerPanel platform - hardcoded database, service and cloud credentials: Hardcoded credentials usedCriticalMay 15, 2024
CyberPower PowerPanel business application - JWT signing key: The JWT signing key is hardcoded in the application, soCriticalMay 15, 2024
CyberPower PowerPanel business application - hardcoded authentication credentials: A hardcoded credential set compiledCriticalMay 15, 2024
CyberPower PowerPanel MQTT message handling: An attacker with MQTT publish permissions can craft messagesHighMay 15, 2024
CyberPower PowerPanel managed devices - shared device certificates: Every managed device uses an identical certificateHighMay 15, 2024
CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIs: Certain utility REST APIs have no authenticationCriticalMay 14, 2024- Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0a: Three defects that together mean every SANnav OVAHighApr 19, 2024
- Terraform (go-getter): Argument injection when go-getter shells out to Git for remote branch discoveryCriticalApr 17, 2024
- Palo Alto PAN-OS: GlobalProtect arbitrary file creationCriticalApr 12, 2024
- Linux nfsd (NFS server): Broken RELEASE_LOCKOWNER handling in nfsd causing state corruptionMediumMar 13, 2024
Moxa NPort W2150A / W2250A wireless device server: A remote attacker can crash or potentially gain code executionHighMar 6, 2024- JetBrains TeamCity: Alternative-path authentication bypassCriticalMar 4, 2024
ConnectWise ScreenConnect: Auth bypass via alternate pathCriticalFeb 21, 2024
ConnectWise ScreenConnect: Path traversal enabling remote code executionHighFeb 21, 2024- Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode): SR670 V2 servers built between roughly June 2021 and JulyLowFeb 16, 2024
- Fortinet FortiOS: SSL-VPN out-of-bounds writeCriticalFeb 9, 2024
- MinIO: Access keys inherit the parent's `admin:*` actions, not just `s3:*`HighJan 31, 2024
- Jenkins: CLI parser expands `@file` into argument contentsCriticalJan 24, 2024
- Jenkins: No origin validation on the CLI WebSocket endpointHighJan 24, 2024
Ivanti Connect Secure: Command injection in web componentsCriticalJan 12, 2024- Pure Storage FlashArray Purity (dormant configuration account): A local account intended only for initial arrayCritical2024
- Pure Storage FlashArray Purity (privileged remote access account): An attacker uses a privileged account to gain remoteCritical2024
- Automated Logic WebCTRL 7.0 / WebCTRL Premium Server / Carrier i-Vu building automation server: Unauthenticated fileCritical2024
- NetApp ONTAP Select Deploy administration utility (hard-coded credentials): MULTI-TENANT ISOLATION: baked-inCritical2024
HPE Cray Parallel Application Launch Service (PALS) authentication bypass: Authentication bypass in the serviceCritical2024- LenelS2 NetBox access control and event monitoring system (<=5.6.1): Unauthenticated remote code executionCritical2024
- Volcano (v1.8.2 and earlier, service account token permissions): MULTI-TENANT ISOLATION: Volcano 1.8.2 shipsCritical2024
- VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticatedCritical2024
- Linux NFS server (nfsd, laundromat vs free_stateid race): A race between the delegation laundromat and a client-issuedCritical2024
- HPE Insight Remote Support (directory traversal to RCE): Directory traversal allowing unauthenticated remote codeCritical2024
- MinIO (admin IAM import API): MULTI-TENANT ISOLATION: the IAM import API can be driven to grant an attackerCritical2024
- Pure Storage FlashArray Purity (remote administrative account creation): An attacker uses a remote administrativeCritical2024
- Pure Storage FlashArray Purity (array admin command execution): A user holding the array admin role executes arbitraryCritical2024
- Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection): A crafted SNMP configuration yieldsCritical2024
- Linux NFS server (nfsd, NFSv4 COMPOUND tag decode): An NFSv4 COMPOUND tag length near U32_MAX overflows the length+4Critical2024
- Cisco Nexus Dashboard Fabric Controller (path traversal to RCE via SCP): A low-privileged authenticated attackerHigh2024
- Cisco Nexus Dashboard Fabric Controller (SQL injection): A read-only NDFC user executes arbitrary SQL on the controllerHigh2024
- Deep Sea Electronics DSE855 generator communications gateway: Six unauthenticated flaws in one device: two stack-basedHigh2024
- Socomec DIRIS Digiware M-70 1.6.9 (Modbus TCP and Modbus RTU-over-TCP): A large cluster of unauthenticated ModbusHigh2024
- VMware Aria Automation (SQL injection): An authenticated user injects SQL and performs unauthorized read/writeHigh2024
- Ceph RADOS Gateway (RGW): MULTI-TENANT ISOLATION: RGW accepts a JWT whose header declares alg "none" and never checksHigh2024
- HPE Insight Remote Support (Java deserialization): Java deserialization letting an unauthenticated attacker executeHigh2024
- Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executesHigh2024
- Intel QuickAssist Technology (QAT) software and driversHigh2024
- NetApp ONTAP 9 role-based access control: A user holding several remote accounts with different roles performs actionsHigh2024
- Ceph RADOS Gateway (RGW): One malformed PUT kills the radosgw process. Sending an object copy with an emptyHigh2024
Kubeflow (centraldashboard-angular backend, email validation regex): A catastrophically backtracking regex in theHigh2024- HPE Insight Remote Support (XXE): Third XXE variant in Insight RS enabling remote information disclosureHigh2024
- Dell OpenManage Server Administrator (XSL hijacking local privilege escalation): A local low-privileged user hijacksHigh2024
- HPE Insight Remote Support (XXE): XML external entity injection allowing remote users to disclose informationHigh2024
- HPE Insight Remote Support (XXE): Second XXE path in Insight RS enabling information disclosureHigh2024
- Lenovo ThinkSystem SMM / SMM2 and FPC (command injection): An authenticated user with elevated privileges executesHigh2024
- Dell CloudLink (cluster component exception handling): A highly privileged remote attacker performs unauthorizedMedium2024
- Cisco UCS Central Software (weak backup encryption): Weak encryption on full-state and configuration backups meansMedium2024
- Dell OpenManage Enterprise (credential disclosure): A low-privileged local user obtains stored credentials from OMEMedium2024
- Dell OpenManage Enterprise (path traversal): An unauthenticated remote attacker reads files from the OME serverMedium2024
- AMD - Global History Register side channel: MULTI-TENANT ISOLATION: A side channel through the branch predictor'sUnscored2024
- AMD Zen 2, Zen 3 and Zen 4 platforms with DDR4 (7/10 Zen 2 and 6/10 Zen 3 devices flipped) and DDR5 (1/10 devices)Unscored2024
2023
- AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016): MULTI-TENANT ISOLATION: Insufficient RMP checkingMediumApr 16, 2026
- Linux i915 GVT-g mediated GPU virtualisation (debugfs teardown): MULTI-TENANT ISOLATION: Companion to the vGPU debugfsHighDec 24, 2025
- Linux HID/amd_sfh - shift out of bounds: A shift operation in the AMD Sensor Fusion Hub driver exceeds the maximumUnscoredOct 22, 2025
- Linux i915 GVT-g mediated GPU virtualisation: MULTI-TENANT ISOLATION: Unsafe cleanup of per-vGPU debugfs stateMediumOct 7, 2025
- Linux x86/MCE - CS register not saved on AMD Zen Instruction Fetch Poison errors: On AMD Zen systems, the InstructionMediumSep 18, 2025
- Linux perf/x86/amd/core - overflow status not cleared for unhandled indices: Unhandled overflow bits are left setMediumMay 2, 2025
- RKE / Rancher (k8s control plane): full-cluster-state configmap in kube-system readable by non-adminsCriticalOct 16, 2024
- AMD SMM communications buffer - TOCTOU (AMD-SB-3003): MULTI-TENANT ISOLATION: A time-of-check-to-time-of-use raceHighAug 13, 2024
- AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003): MULTI-TENANT ISOLATION: The IOMMU is not re-initializedMediumAug 13, 2024
Acronis Cyber Infrastructure: Default passwordsCriticalJul 24, 2024- Linux x86/mm - pfn_to_kaddr() 64-bit input handling (SNP support code): On 64-bit platforms the pfn_to_kaddr() macroMediumMay 17, 2024
- Intel Data Center GPU Max Series 1100 / 1550: An improper conditions check lets a privileged local user takeMediumMay 16, 2024
Ceph RGW (IBM Spectrum Fusion HCI): Improper bucket access lets an actor perform unauthorized actions in RGWMediumMay 14, 2024
A10 Thunder ADC (FileMgmtExport): An authenticated attacker can walk outside the intended export directoryHighMay 3, 2024- Fortinet FortiClient EMS: Unauthenticated SQL injectionCriticalMar 12, 2024
Lustre (incorrect access control, 2.13.x-2.15.x before 2.15.4): TENANT ISOLATION: incorrect access control in LustreCriticalMar 7, 2024- Citrix NetScaler ADC/Gateway: Buffer overflow causing denial of service when configured as Gateway or AAA vserverHighJan 17, 2024
- Citrix NetScaler ADC/Gateway: Code injection on the management interfaceMediumJan 17, 2024
- GitLab: Password reset email deliverable to an unverified addressCriticalJan 12, 2024
Ivanti Connect Secure: Web-component authentication bypass reaching restricted resourcesHighJan 12, 2024
OpenSSH through 10.0 - mm_answer_authpassword uses an integer 'authenticated' flag that does not resist a single bitHighDec 24, 2023- Keycloak: Wildcard in the JARM form_post.jwt response modeMediumDec 18, 2023
- Keycloak: Redirect scheme filtering bypassed by appending a wildcardMediumDec 14, 2023
- OpenZFS: Block-cloning path can replace file contents with zero bytes, potentially disabling security mechanismsHighNov 24, 2023
- AMD SMM Supervisor (AMD-SB-7011): MULTI-TENANT ISOLATION: The highest-scored AMD platform CVE in this database at 9.8CriticalNov 14, 2023
- AMD Radeon Graphics display driver - input validation: Improper input validation in the Radeon display driver letsHighNov 14, 2023
- AMD Radeon RX Vega M graphics driver installer - signature verification: The driver package launchesMediumNov 14, 2023
- OpenVINO Model Server: Input-validation flaw in OpenVINO Model Server reachable without authenticationMediumNov 14, 2023
Samba: Path traversal in client pipe namesCriticalNov 3, 2023
Samba: SMB client can truncate files despite read-only permissions when acl_xattr ignores system ACLsMediumNov 3, 2023- Linux NVMe-oF (nvmet-tcp): Use-after-free/double-free in nvmet_tcp_free_cryptoHighNov 1, 2023
- Elasticsearch: Crafted _search query stringMediumOct 26, 2023
- RabbitMQ: HTTP API enforces no request body limitMediumOct 25, 2023
- AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory access: MULTI-TENANT ISOLATIONHighOct 17, 2023
- MySQL Server: InnoDB flaw - a high-privileged network attacker can hang or repeatedly crash the serverMediumOct 17, 2023
- Citrix NetScaler ADC/Gateway: "CitrixBleed" - memory overread leaking valid session tokensCriticalOct 10, 2023
- HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesetsHighSep 29, 2023
- JetBrains TeamCity: Authentication bypass leading to remote code execution on TeamCity ServerCriticalSep 19, 2023
- Argo CD: repo-server extracts a user-controlled tar.gz without size validationMediumSep 7, 2023
Digi RealPort protocol (Digi console/terminal servers): RealPort is the protocol Digi console servers use to exposeCriticalAug 31, 2023- Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2a: Remote unauthenticated users can bypass webHighAug 31, 2023
- Broadcom LSI Storage Authority (LSA) - on-disk credential/key storage on Linux and Windows: The keys LSA usesMediumAug 15, 2023
- AMD SMM - memory corruption (AMD-SB-4003): MULTI-TENANT ISOLATION: Memory corruption reachable in System ManagementHighAug 8, 2023
- Keycloak: OIDC authentication flaw - attacker reusing data from a same-realm request impersonates a userMediumAug 4, 2023
- Citrix NetScaler ADC/Gateway: Unauthenticated remote code execution on the gateway applianceCriticalJul 19, 2023
- Grafana: Azure AD accounts validated on the mutable, non-unique email claimCriticalJun 22, 2023
- Fortinet FortiOS / FortiProxy SSL-VPN: A heap-based buffer overflow in the SSL-VPN daemon lets a remoteCriticalJun 13, 2023
- Apache Guacamole: Miscalculated instruction lengths during the Guacamole handshakeMediumJun 7, 2023
Progress MOVEit Transfer: Unauthenticated SQL injection into the web appCriticalJun 2, 2023
DMTF libspdm - SPDM Requester timeout handling: A libspdm Requester stores the Responder's CTExponentMediumJun 1, 2023- GitLab: Unauthenticated path traversal reads arbitrary server files when an attachment sits under 5+ nested groupsCriticalMay 26, 2023
- etcd: LeaseTimeToLive exposes key names to a user without read permission on those keysLowMay 11, 2023
DMTF libspdm - SPDM session establishment (reference implementation used in GPU/device attestation): MULTI-TENANTCriticalMay 8, 2023
CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux): A default passwordCriticalApr 24, 2023
CyberPower PowerPanel Business - default.cmd file upload: Unrestricted upload of a dangerous file type into default.cmdCriticalApr 24, 2023
Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - device credential endpoints: IncorrectHighApr 18, 2023
Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - Device File Transfer settings: MissingHighApr 18, 2023
Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpoint: Code injectionHighApr 18, 2023- MinIO: Windows deployments fail to filter `\`HighMar 22, 2023
- MinIO: Crafted request bypasses PostPolicyBucket metadata bucket-name checkHighMar 22, 2023
- MinIO: Cluster returns all env vars incl. MINIO_SECRET_KEY and MINIO_ROOT_PASSWORDHighMar 22, 2023
- Veeam Backup & Replication: Encrypted credentials in the configuration database can be obtainedHighMar 10, 2023
HAProxy (before 2.7.3): HAProxy's HTTP/1 header parser accepts empty header field names, which can be used to makeCriticalFeb 14, 2023- Apache Kafka Connect: Attacker able to create/modify a connector sets a SASL JAAS JndiLoginModule configHighFeb 7, 2023
- Netdata: Agent MACHINE GUID is readable and reusableMediumJan 14, 2023
- ZKTeco-based OEM biometric access terminals (ZKTeco ProFace X, Smartec ST-FR043/ST-FR041ME and rebadged equivalents)Critical2023
- VMware Aria Automation (missing access control): An authenticated user reaches remote organizations and workflows theyCritical2023
- Pure Storage FlashBlade management interface authentication: MULTI-TENANT ISOLATION: an attacker authenticates to theCritical2023
IBM Storage Scale session management: MULTI-TENANT ISOLATION: an authenticated user steals or fixates another user'sHigh2023
OpenPMIx (PMIx library used by Slurm and Open MPI for job launch): A race in PMIx library code that executes with UID 0High2023
HPE OneView (command injection with local privilege escalation): A low-privileged local user on the OneView applianceHigh2023- NetApp ONTAP 9 HTTP service: An unauthenticated attacker crashes the ONTAP HTTP service, taking down the management andHigh2023
- Software House iSTAR Ultra, Ultra LT, Ultra G2 and Edge G2 door controllers: An unauthenticated user can logHigh2023
- ZKTeco BioTime v8.5.5 (iclock API path traversal): Unauthenticated arbitrary file read on the BioTime serverHigh2023
- KNX devices using KNX Connection Authorization Option 1 (BCU key): An attacker sets the BCU key on KNX devicesHigh2023
- Johnson Controls Metasys NAE55 / SNE / SNC network engines and Facility Explorer F4-SNC (before 11.0.6 / 12.0.4)High2023
Slurm (NULL pointer dereference in RPC handling): A crafted message crashes the Slurm daemon. On slurmctld that stallsHigh2023
HPE OneView (clusterService authentication bypass to DoS): Authentication bypass against the OneView cluster serviceHigh2023
Kubeflow (central dashboard, reflected cross-site scripting): Reflected XSS in the Kubeflow dashboard runs attackerMedium2023- ZKTeco BioAccess IVS v3.3.1 access control platform: An unauthenticated attacker can open and close any doorMedium2023
- Pure Storage FlashBlade object store protocol: An authenticated object-store user degrades both data access andMedium2023
- FlyteAdmin (list endpoints, SQL injection through list filters): MULTI-TENANT ISOLATION: FlyteAdmin's list endpointsLow2023
2022
- Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttling: A race between AMD PMU enablementMediumMay 1, 2025
- Harbor registry: P2P preheat execution logs readable/updatable by any authenticated user via job ID enumerationHighNov 14, 2024
- Linux swiotlb - info leak with DMA_FROM_DEVICE bounce buffers: MULTI-TENANT ISOLATION: The software IO TLB leaksMediumJul 16, 2024
IBM Storage Scale Container Native Storage Access (namespace boundary): TENANT ISOLATION: a local attacker can initiateHighFeb 17, 2024
IBM Spectrum Scale Container Native Storage Access: A local user obtains root privileges through the Spectrum ScaleHighApr 29, 2023
IBM Spectrum Scale / Storage Scale Container Native Storage Access: TENANT ISOLATION: programs running insideHighApr 26, 2023- Intel C++ Compiler Classic / oneAPI toolkits (Unicode source handling): Improper handling of Unicode bidirectionalHighFeb 16, 2023
- Intel oneAPI DPC++/C++ compiler (homoglyph rendering): Homoglyph characters are not visually distinguishedHighFeb 16, 2023
- Intel oneAPI Data Analytics Library (oneDAL): An uncontrolled library search path: the component loads a shared libraryMediumFeb 16, 2023
- Intel MPI Library (oneAPI HPC Toolkit): An uncontrolled library search path: the component loads a shared libraryMediumFeb 16, 2023
- Intel oneAPI Deep Neural Network Library (oneDNN): An uncontrolled library search path: the component loads a sharedMediumFeb 16, 2023
- Intel oneAPI OpenMP runtime: An uncontrolled library search path: the component loads a shared library by nameMediumFeb 16, 2023
- Intel oneAPI DPC++/C++ compiler runtime: An uncontrolled library search path: the component loads a shared libraryMediumFeb 16, 2023
- Intel oneAPI Collective Communications Library (oneCCL): An uncontrolled library search path: the component loadsMediumFeb 16, 2023
Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storage: DCE stores device passwordsHighJan 30, 2023
Schneider Electric Data Center Expert (versions prior to v7.9.0) - Java deserialization: Unsafe deserialization of dataHighJan 30, 2023
Imagination PowerVR GPU driver - cache subsystem information page: The driver's cache-subsystem information pageMediumJan 26, 2023- Ceph: ceph-crash.service local privilege escalation to root plus privileged crash-dump disclosureHighJan 17, 2023
- Fortinet FortiOS: SSL-VPN heap-based buffer overflowCriticalJan 2, 2023
- Citrix ADC/Gateway: SAML SP/IdP configCriticalDec 13, 2022
- Brocade Fabric OS (unauthenticated remote code execution): Unauthenticated remote code execution on a Fibre ChannelCriticalDec 8, 2022
- Prometheus (exporter-toolkit): Poisoning the built-in auth cache bypasses basic-auth on exportersMediumNov 29, 2022
Tailscale (Windows client): Local API bound to a TCP socketCriticalNov 23, 2022- Linux nfsd (NFS server): NFSD buffer overflow - a client can force the send buffer to overflow the page arrayHighNov 4, 2022
- Brocade Fabric OS CLI: A remote authenticated attacker can act beyond their role through the Fabric OS CLIHighOct 25, 2022
- Fortinet FortiOS/FortiProxy: Auth bypass via an alternate pathCriticalOct 18, 2022
- Grafana: A user can block another user's login by registering their email address as a usernameMediumOct 13, 2022
- HashiCorp Consul: Internal RPC endpoint does not check multiple SAN URIs in a CSRMediumSep 23, 2022
- PostgreSQL: Autovacuum, REINDEX, CLUSTER etc. apply protections too lateHighAug 31, 2022
Samba (AD DC): KDC and kpasswd share keysHighAug 25, 2022
Samba (AD DC): KDC accepts kpasswd requests encrypted with any key it knowsHighAug 25, 2022- Intel Data Center Manager: Improper access control in Data Center Manager lets an unauthenticated attackerHighAug 18, 2022
- Intel Data Center Manager: Improper neutralisation (injection) in Data Center Manager lets an authenticated userHighAug 18, 2022
Ampere Altra before 1.08g and Altra Max before 2.05a - return address prediction: An attacker can controlHighAug 17, 2022- Ceph Manager (volumes plugin): Owner of one CephFS share can read/write any share or the entire file systemCriticalJul 25, 2022
- Cisco Nexus Dashboard (web UI / CSRF): One of a batch of unauthenticated flaws in Nexus Dashboard that together allowCriticalJul 21, 2022
- Grafana: Stored XSS via Unified AlertingHighJul 15, 2022
- Brocade SANnav Management Portal - Zone management endpoints, before SANnav 2.2.0: SQL injection in multiple endpointsCriticalMay 6, 2022
- F5 BIG-IP (iControl REST): An unauthenticated attacker can send undisclosed requests to the iControl REST managementCriticalMay 5, 2022
- Redis: Lua environment weakness lets a user inject code that runs with another Redis user's privilegesLowApr 27, 2022
- Redis: Crafted Lua script triggers a NULL pointer dereferenceLowApr 27, 2022
- MySQL Server: InnoDB flaw allowing a high-privileged network attacker to cause a repeatable DoSMediumApr 19, 2022
- MinIO: Non-admin user can create service accounts for root/admin users and assume their policiesHighApr 12, 2022
- Redis: Debian/Ubuntu packaging leaves a Lua sandbox escapeCriticalFeb 18, 2022
Zabbix: Unverified user login in session data (SAML SSO enabled)CriticalJan 13, 2022
Zabbix: Some setup.php steps reachable by unauthenticated usersLowJan 13, 2022
Windows Boot Manager: Secure Boot bypass exploited in the wild by the BlackLotus UEFI bootkitMediumJan 11, 2022- Software House iSTAR Ultra door controller (before 6.8.9.CU01): Unauthenticated command injection giving rootCritical2022
- HID Mercury intelligent controllers sold by Carrier LenelS2 (LNL-X2210/X2220/X3300/X4420/4420Critical2022
- Pure Storage Purity//FA and Purity//FB management interface (exposed credential): MULTI-TENANT ISOLATION: a passwordCritical2022
- Linux NFS server (nfsd, nfssvc_decode_writeargs): The NFSv2/v3 write argument decoder has no lower bound on the lengthCritical2022
- FlyteConsole (cors_proxy endpoint): MULTI-TENANT ISOLATION: FlyteConsole's cors_proxy forwards attacker-chosen URLs, soCritical2022
- HTCondor (CLAIMTOBE authentication method): MULTI-TENANT ISOLATION: Once a user has authenticated to a daemon withHigh2022
- Honeywell Alerton Visual Logic, Ascent Control Module (ACM) and Compass 1.6.5: Unauthenticated program writesHigh2022
- Pure Storage Purity//FA and Purity//FB restricted shell (Python environment variables): A logged-in user manipulatesHigh2022
- Pure Storage Purity//FA and Purity//FB restricted shell (environment variables): A second route out of the restrictedHigh2022
- NetApp ONTAP SnapLock on FlexGroup volumes: An authenticated remote user modifies or deletes WORM-locked data beforeHigh2022
- Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191: Use-after-freeHigh2022
IBM Storage Scale Container Native Storage Access (pod security context): MULTI-TENANT ISOLATION: a local user in aHigh2022
IBM Spectrum Scale container image (command execution): A local attacker runs arbitrary commands inside the SpectrumHigh2022- Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi): Unauthenticated arbitrary file read off the gatewayHigh2022
- FlyteAdmin (built-in OAuth authorization server, default client secret hashes): MULTI-TENANT ISOLATION: Turning onHigh2022
IBM Storage Scale Container Native Storage Access (network namespace exposure): MULTI-TENANT ISOLATION: hosts outsideHigh2022
Schneider Electric APC NetBotz 4 environmental appliances (355/450/455/550/570, V4.7.0 and prior): No rate limitingHigh2022- GlusterFS (dht translator, dht_setxattr_mds_cbk): A use-after-free in the distributed-hash translator crashes the brickHigh2022
- MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intendedHigh2022
IBM Spectrum Scale Container Native Storage Access (CSI volume handling): MULTI-TENANT ISOLATION: anyone who can createMedium2022
IBM Spectrum Scale Data Access Services (DAS): An authenticated DAS user inserts code that manipulates clusterMedium2022- FlyteAdmin (external IdP access token / ID token expiration check): MULTI-TENANT ISOLATION: FlyteAdmin does not enforceMedium2022
Slurm (openSUSE slurm-testsuite packaging): The openSUSE slurm testsuite package ships files with permissive defaultMedium2022
Rittal CMC III cabinet lock / access-card system: The access cards used to open control cabinets secured with RittalMedium2022
BeeGFS (client-to-metadata/storage service authentication, connAuthFile): MULTI-TENANT ISOLATION: Class entry, not aUnscored2022
2021
- AMD PSP1 Configuration Block (APCB) parsing: MULTI-TENANT ISOLATION: An out-of-bounds memory write while the platformHighAug 13, 2024
- AGESA Boot Loader (ABL) - SPI ROM header input validation (AMD-SB-3003): The AGESA Boot Loader does not properlyLowAug 13, 2024
- AMD TEE / ASP bootloader syscall input validation: Insufficient validation of syscall inputs in the AMD trustedMediumMay 9, 2023
- etcd: Authentication flaw via the debug functionCriticalApr 4, 2023
- Ceph: Key length incorrectly passed to the encryption algorithmMediumAug 25, 2022
Imagination PowerVR GPU driver - pinned memory lifecycle: MULTI-TENANT ISOLATION: an unprivileged app allocates pinnedCriticalAug 24, 2022
Imagination PowerVR GPU driver - memory residue: MULTI-TENANT ISOLATION: an unprivileged application gets the GPUUnscoredAug 24, 2022
Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05HighAug 17, 2022- AMD Zen 1 / Zen 2 / Zen 3 - execution unit scheduler queue contention (SMT): MULTI-TENANT ISOLATION: AMD's splitMediumAug 10, 2022
- AMD AGESA Boot Loader (ABL) / ASP stage-2 bootloader: MULTI-TENANT ISOLATION: A malicious or compromised UserMediumMay 12, 2022
- AMD CPU core logic - core hang triggered from an unprivileged VM: MULTI-TENANT ISOLATION: Specific code executedMediumMay 11, 2022
Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: Path traversal to remote code executionCriticalApr 13, 2022
Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: OS command injection over the networkCriticalApr 13, 2022
Moxa NPort IAW5000A-I/O serial device server: The built-in web server doesn't validate input properly, letting a remoteCriticalApr 1, 2022- ClickHouse: Attacker-controlled offset in the LZ4 codecHighMar 14, 2022
- ClickHouse: Second heap out-of-bounds read in LZ4::decompressImpl reachable from a client queryHighMar 14, 2022
- PostgreSQL: With cert/trust+clientcert auth, a MITM can inject arbitrary SQL at connection setupHighMar 4, 2022
- Brocade Fabric OS (hard-coded credentials): Documented hard-coded credentials in Brocade Fabric OSCriticalFeb 21, 2022
Samba (SMB gateway): Out-of-bounds heap read/write in vfs_fruitHighFeb 21, 2022- AMD System Management Mode (SMM) interrupt handler: MULTI-TENANT ISOLATION: A flaw in the AMD SMM interrupt handlerHighFeb 16, 2022
- Intel SPS (HECI subsystem compartmentalisation): Insufficient compartmentalisation in the HECI interfaceMediumFeb 9, 2022
- MinIO: Hand-crafted admin API call updates a user's policyHighDec 27, 2021
Microsoft iSNS Server service (Internet Storage Name Service for iSCSI discovery): Memory corruption in the iSNS ServerCriticalDec 15, 2021- Grafana: Unauthenticated directory traversal via /public/plugins/<id>/HighDec 7, 2021
- PC-DDR4 / LPDDR4X DRAM - Target Row Refresh mitigation: Non-uniform Rowhammer patterns triggered bit flips on every oneCriticalNov 16, 2021
- AMD System Management Unit (SMU) mailbox interface: A malicious user can manipulate SMU mailbox entries and reachHighNov 16, 2021
- Broadcom Emulex HBA Manager / OneCommand Manager (Fibre Channel and FC-NVMe HBAs), before 11.4.425.0 and 12.8.542.31CriticalNov 12, 2021
HPE ProLiant Gen10 System ROM (security restriction bypass): A local bypass of security restrictions in the System ROMMediumNov 1, 2021- Grafana: Unauthenticated access to snapshots via /api/snapshots/:keyCriticalOct 5, 2021
- Cisco APIC / Cloud APIC (API endpoint): Unauthenticated arbitrary file read and write on the APICCriticalAug 25, 2021
- Dell OpenManage Enterprise (remote code execution): Remote code execution on the OpenManage Enterprise consoleCriticalAug 9, 2021
- Terraform Enterprise: Missing authorization on a subset of run-token API requestsHighJul 20, 2021
- linuxptp / ptp4l (PTP message forwarding): A missing length check when ptp4l forwards a PTP message between ports leaksHighJul 9, 2021
- linuxptp / ptp4l (transparent clock on little-endian): A crafted PTP packet against ptp4l running as a transparentHighJul 9, 2021
- RabbitMQ: Unsanitized username rendered in the management UILowJun 28, 2021
- Ceph RGW: HTTP header injection via a newline in the CORS ExposeHeader tagMediumMay 17, 2021
- GitLab: Image files passed unvalidated to a file parser (ExifTool)CriticalApr 23, 2021
- Eaton Intelligent Power Manager (IPM) prior to 1.69: PHYSICAL. Unauthenticated remote code execution on Eaton'sCriticalApr 13, 2021
- Eaton Intelligent Power Manager (IPM) prior to 1.69 - dynamic eval: Unauthenticated eval injection: user-controlledHighApr 13, 2021
- Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.js: Unauthenticated arbitrary file deletionHighApr 13, 2021
SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01): A zero-length PDU sent where data is expectedHighMar 13, 2021- Linux iSCSI: iSCSI netlink structures lack length checksHighMar 7, 2021
- Linux iSCSI: Unprivileged user can craft Netlink messages to scsi_transport_iscsiHighMar 7, 2021
- Linux iSCSI: Kernel pointer leak - iscsi_transport handle exposed to unprivileged users via sysfsMediumMar 7, 2021
- Cisco ACI Multi-Site Orchestrator (Application Services Engine): TENANT ISOLATION: complete unauthenticatedCriticalFeb 24, 2021
- Cisco Nexus 3000/9000 (internal file management service): Unauthenticated remote file write, read and delete as rootCriticalFeb 24, 2021
- Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN): TENANT ISOLATION: a device plugged into a normal front-panelHighFeb 24, 2021
Nagios XI: OS command injection in the windowswmi config wizard (authenticated)HighFeb 15, 2021
Nagios XI: OS command injection in the switch config wizardHighFeb 15, 2021
Nagios XI: OS command injection in the cloud-vm config wizardHighFeb 15, 2021- tcmu-runner 1.3.x - 1.5.2 (userspace backstore handler for the Linux LIO target, used by Ceph iSCSI gateways and otherHighJan 13, 2021
- HTCondor (condor_credd): condor_credd can be told to create or write files as root outsideCritical2021
- Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllers: A cluster of critical flawsCritical2021
- HTCondor (IDTOKENS authentication): MULTI-TENANT ISOLATION: A flaw in IDTOKENS lets a user authenticate as another userHigh2021
- MinIO (IAM policy engine): MULTI-TENANT ISOLATION: a regular user can step outside the policy restrictions applied toHigh2021
- HTCondor (SciTokens authentication): MULTI-TENANT ISOLATION: A SciToken is granted more authorization than the token'sHigh2021
- HTCondor (condor_schedd, condor_collector): MULTI-TENANT ISOLATION: A user with nothing more than READ access to theHigh2021
- HTCondor (S3 file transfer, daemon logs and job ClassAds): MULTI-TENANT ISOLATION: Pre-signed S3 URLs for a job's inputHigh2021
IBM Spectrum Scale core component (format string handling): A user with a shell on any node that runs Storage ScaleHigh2021- NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removingHigh2021
- HTCondor (daemon-to-daemon channel, negotiator/startd/schedd): MULTI-TENANT ISOLATION: Secret material crosses theHigh2021
- Ceph MON (CephX authentication): MULTI-TENANT ISOLATION: the monitor does not sanitize other_keys when handlingHigh2021
Slurm (slurmdbd, AccountingStoreFlags=job_script / job_env): MULTI-TENANT ISOLATION: When the site turns on job-scriptMedium2021- Intel 82599 Ethernet Controllers and Adapters - network-on-chip shared-resource isolation: Improper isolation of sharedMedium2021
IBM Spectrum Scale file audit logging retention: A privileged administrator deletes audit records before theirMedium2021
IBM Spectrum Scale file audit logging: A local user touches files without the access being recorded, so the audit trailLow2021- DDR4 DRAM with in-DRAM TRR; a coupling effect that reaches rows at distance two rather than immediate neighboursUnscored2021
2020
IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1: TENANT ISOLATION: unauthorized access to user dataCriticalMay 24, 2022- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (improper input validation) reachableMediumFeb 17, 2021
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (insufficient access control leadingMediumFeb 17, 2021
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (uncontrolled resource consumption)MediumFeb 17, 2021
- Replay Protected Memory Block (RPMB) protocol as specified for eMMC, UFS and ALL versions of NVMeMediumNov 18, 2020
- Intel Data Center Manager Console: Improper input validation in the DCM Console lets an authenticated user escalateHighNov 12, 2020
- Brocade Fabric OS REST API: Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remoteCriticalSep 25, 2020
APC PowerChute Business Edition (v9.0.x and earlier): PHYSICAL. PowerChute runs the shutdown script that firesHighAug 31, 2020
Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management): The earlier cluster on the same consoleCriticalAug 25, 2020
Marvell QConvergeConsole (QLogic adapter management): Remote code execution on QConvergeConsole, the managementHighAug 25, 2020- Fortinet FortiOS SSL-VPN: A logic flaw lets a user who changes their login case (e.gCriticalJul 24, 2020
- ntpd (transmit timestamp prediction): A remote attacker who can predict transmit timestamps can crash ntpd or, worseHighJun 4, 2020
- AMD ATI atillk64.sys - physical memory mapping driver: MULTI-TENANT ISOLATION: The AMD ATI atillk64.sys driver exposesHighApr 27, 2020
- ntpd (NTP.org reference implementation): An off-path attacker can block a node's unauthenticated time synchronizationHighApr 17, 2020
- targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)HighApr 15, 2020
- DDR4 / LPDDR4 DRAM - Target Row Refresh mitigation: Many-sided Rowhammer defeats the in-DRAM Target Row RefreshUnscoredMar 10, 2020
Slurm (Gentoo ebuild pkg_postinst): The Gentoo packaging runs chown across paths on the live root filesystem duringCritical2020- Ceph CephX authentication protocol: MULTI-TENANT ISOLATION: CephX does not correctly bind client identity, so anHigh2020
Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1: Authenticated file uploadHigh2020
IBM Spectrum Scale / Storage Scale core daemon (cluster RPC transport): MULTI-TENANT ISOLATION: an attacker who canHigh2020- Ceph MON / MGR (ceph-mon, ceph-mgr): MULTI-TENANT ISOLATION: ceph-mon and ceph-mgr fail to enforce the caps on anHigh2020
IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions): With specific debug settings enabled, LSFHigh2020
IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials): MULTI-TENANT ISOLATION: A user who is merelyHigh2020- Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills theHigh2020
- Ceph dashboard (ceph-mgr dashboard module): An unauthenticated HTTP request with traversal sequences reads arbitraryHigh2020
IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can sendHigh2020- CephFS (via OpenStack Manila native driver): MULTI-TENANT ISOLATION: a Manila user can request access for an existingHigh2020
- RPMB protocol message authentication subsystem in Intel TXE before 4.0.30 (replay-protected memory block)Medium2020
IBM Spectrum Scale mmfsd daemon (RPC request handling): A local attacker floods mmfsd with RPC requests and crashes itMedium2020
Slurm (X11 forwarding, xauth magic-cookie setup): MULTI-TENANT ISOLATION: Slurm shells out to xauth to install a user'sLow2020- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: MULTI-TENANT ISOLATION: a user in one SVM determinesLow2020
- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: MULTI-TENANT ISOLATION: a user in one SVM enumerates theLow2020
- AMD Zen 1 / Zen+ / Zen 2 - L1D cache way predictor: MULTI-TENANT ISOLATION: AMD's L1D way predictor hashes virtualUnscored2020
2019
Vertiv Avocent UMG-4000 universal management gateway: Every command the UMG-4000's web interface runs executes as rootHighMar 30, 2020
Vertiv Avocent UMG-4000 universal management gateway: An authenticated admin can plant a maliciously named fileMediumMar 30, 2020
Lustre ptlrpc module (server-side client packet validation): TENANT ISOLATION: a Lustre client can send a crafted RPCCriticalJan 27, 2020
Lustre ptlrpc / mdt modules (client-driven server panic family): FABRIC DOS: the head of a family of ten Lustre defectsHighJan 27, 2020
Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions throughHighDec 19, 2019
BeeGFS (beegfs-ctl / metadata server): TENANT ISOLATION: authentication bypass by talking directly to a BeeGFS metadataCriticalDec 5, 2019- Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270: Same class of in-flight data leakMediumNov 14, 2019
- Cisco Nexus 9000 ACI Mode (LLDP subsystem): A buffer overflow in the LLDP subsystem of Nexus 9000 switches in ACI modeHighJul 31, 2019
CyberPower PowerPanel Business Edition 3.4.0 Agent/Center: Cross-site request forgery across all forms in the webHighJul 10, 2019- DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issue: TurnsLowJun 13, 2019
Slurm (slurmdbd, sacctmgr archive load): MULTI-TENANT ISOLATION: A second SQL injection path into SlurmDBD, this oneCritical2019- HTCondor (condor_startd, condor_schedd, condor_shadow): MULTI-TENANT ISOLATION: One CVE covering four separateCritical2019
- NetApp ONTAP Select Deploy administration utility (HTTP service): MULTI-TENANT ISOLATION: an unauthenticated attackerCritical2019
- NetApp ONTAP Select Deploy administration utility (credential transport): Deploy sends its credentials in plaintext, soCritical2019
- NetApp ONTAP Select Deploy administration utility (code injection): MULTI-TENANT ISOLATION: an unauthenticated remoteCritical2019
Slurm (32-bit RPC handling): Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control ofCritical2019- Optergy Proton / Enterprise building management platform: A backdoor console giving remote root code executionCritical2019
- Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra service: Unauthenticated remote code executionCritical2019
IBM Spectrum Scale management GUI: Any authenticated GUI user - including a low-privilege monitoring account - runsHigh2019- Altair PBS Professional / OpenPBS (pbs_mom): MULTI-TENANT ISOLATION: pbs_mom, the daemon that executes jobs on everyHigh2019
- MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controlsHigh2019
IBM Spectrum Scale administrative command path: A local unprivileged user becomes root on a Storage Scale node byHigh2019- Ceph RADOS Gateway (RGW, Beast frontend): An unauthenticated client can crash radosgw by sending valid headers followedHigh2019
Slurm (srun --uid): MULTI-TENANT ISOLATION: srun --uid drops privileges in the wrong order, so a step launched throughHigh2019
Lustre (mdt module, mdt_object_remote): A client sends a packet with unvalidated fields and the metadata serverHigh2019
Lustre (ptlrpc module): Out-of-bounds write in the RPC layer, reachable by a client that lies about packet field sizes.High2019
Lustre (ptlrpc module): A second out-of-bounds access in ptlrpc triggered by unvalidated client packet fields, endingHigh2019
Lustre (ptlrpc module): Out-of-bounds read in ptlrpc leading to a server panic. The read primitive also means serverHigh2019
Lustre (ptlrpc module, lm_bufcount handling): A client that modifies the lm_bufcount field walks the server off the endHigh2019
Lustre (mdt module, MDT Body eadatasize): An oversized eadatasize field in an MDT request drives the metadata serverHigh2019
Lustre (ptlrpc, osd_map_remote_to_local): Out-of-bounds access in the object-storage mapping path, reachable from aHigh2019
Lustre (mdt module): Another unvalidated-field out-of-bounds access in the metadata server, ending in a panic. SameHigh2019- NetApp Clustered Data ONTAP (unauthenticated information disclosure): An attacker with no account extracts sensitiveHigh2019
- NetApp ONTAP Select Deploy administration utility (privilege escalation): An administrative user of the Deploy utilityHigh2019
Slurm (slurmdbd.conf file permissions): slurmdbd.conf is installed world-readable, which leaks the accountingMedium2019- PCIe Address Translation Services on hosts using an IOMMU/SMMU for device isolationUnscored2019
- PCIe Address Translation Services on hosts using an IOMMU/SMMU for device isolationUnscored2019
2015
2019-2026
2018
Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0: TENANT ISOLATION: CC-SG is Raritan's single-pane-of-glassCriticalNov 18, 2019- Intel Core and Xeon CPUs - INTEL-SA-00210: This one is availability, not confidentiality, and it is the mostMediumNov 14, 2019
- Nouveau display driver (in-tree Linux nouveau, NV117): Remote denial of service against a workstation or node runningMediumApr 1, 2019
- Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitiveCriticalDec 3, 2018
Schneider Electric Data Center Expert 7.5.0 and earlier - zip upload: A crafted zip uploaded through the DCE UI canHighNov 30, 2018- Cisco IOS XE MACsec Key Agreement (MKA over EAP-TLS): TENANT ISOLATION: a logic error in MKA over EAP-TLS letsHighOct 5, 2018
HPE iLO3/4/5: Arbitrary code execution on the iLOHighSep 27, 2018- Intel Data Center Manager SDK (reference UI): The DCM SDK's reference UI allows an unauthenticated remote attackerCriticalSep 12, 2018
HPE iLO3/4/5: Remote unauthenticated denial of service against the management controllerHighAug 14, 2018
HPE iLO4 / iLO5: Remote code execution on the management controllerHighAug 6, 2018- ntpq / ntpdc (NTP 4.2.8p11 client utilities): Stack buffer overflow in the ntpq and ntpdc command-line tools via a longCriticalJun 20, 2018
Kemp LoadMaster (LMOS): A flaw in session management lets a remote, unauthenticated attacker bypass the LoadMaster'sCriticalMay 25, 2018- AMD EPYC / Ryzen - Hardware Validated Boot enforcement: MULTI-TENANT ISOLATION: Hardware Validated Boot is not properlyCriticalMar 22, 2018
- AMD EPYC Server - protected memory region access control: MULTI-TENANT ISOLATION: Insufficient access controlCriticalMar 22, 2018
- ntpd (protocol engine, zero-origin timestamp): Continually sending packets with a zero-origin timestamp lets a remoteHighMar 6, 2018
- Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api): rbd-target-api ships with the Werkzeug debug console enabledCritical2018
Slurm (slurmdbd accounting database daemon): MULTI-TENANT ISOLATION: SQL injection into SlurmDBD gives an attacker readCritical2018- GlusterFS (brick, server-rpc-fops.c): Multiple stack buffer overflows from fixed-size alloca() allocations in the brickHigh2018
- GlusterFS (brick, gfs3_symlink_req): MULTI-TENANT ISOLATION: symlink creation is not confined to the volume, so aHigh2018
- NetApp Clustered Data ONTAP export policy enforcement (SMBv2/SMBv3): MULTI-TENANT ISOLATION: export policy rules markedHigh2018
- Ceph MON (ceph-mon): MULTI-TENANT ISOLATION: the monitor accepts pool create/delete and snapshot operations from anyHigh2018
- GlusterFS (brick, gfs3_mknod_req): MULTI-TENANT ISOLATION: a crafted mknod RPC traverses out of the volume and writes aHigh2018
- GlusterFS (glusterd, auth.allow): MULTI-TENANT ISOLATION: the auth.allow option does not actually restrict who mayHigh2018
IBM Spectrum Scale daemon (GSKit cryptographic library dependency): MULTI-TENANT ISOLATION: a local attacker takesHigh2018- GlusterFS (brick, mknod): MULTI-TENANT ISOLATION: mknod can create device nodes that point at real devices on theHigh2018
- Ceph CephX authentication protocol: MULTI-TENANT ISOLATION: an attacker who sniffs the storage network can replay aHigh2018
- Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm): The IntelliSlot cardHigh2018
- SPI flash descriptor region configuration on a wide range of Supermicro boards: Any software running with sufficientMedium2018
- GlusterFS (glusterd management): MULTI-TENANT ISOLATION: an authenticated TLS client can use gluster cli --remote-hostMedium2018
- GlusterFS (dict_unserialize): MULTI-TENANT ISOLATION: a negative key length in a serialized dict makes the server readMedium2018
- Ceph CephX authentication protocol: MULTI-TENANT ISOLATION: the CephX signature calculation can be bypassed, so anMedium2018
IBM Spectrum Scale / GPFS node file access path: MULTI-TENANT ISOLATION: an unprivileged but authenticated user on aMedium2018
IBM GPFS command line utility: Any unprivileged user with a shell on a GPFS node can force GPFS down on that nodeMedium2018
Slurm (user_name / gid field handling): Slurm trusts the user_name and gid fields carried in job RPCs instead ofMedium2018
IBM Spectrum LSF (job submission, file permissions): MULTI-TENANT ISOLATION: Weak file permissions in the LSF installMedium2018
IBM Spectrum Scale Local Read Only Cache (LROC): MULTI-TENANT ISOLATION: with LROC enabled, a read of one file canLow2018- ECC DDR3 server memory on Intel Xeon (Haswell, Sandy Bridge) and AMD Opteron platformsUnscored2018
- ECC DDR3 server memory on Intel Xeon (Haswell, Sandy Bridge) and AMD Opteron platformsUnscored2018
2017
HPE iLO4: Authentication bypass and remote code execution — the "29 A's" `Connection` header bugCriticalFeb 15, 2018
HPE iLO2: Authentication bypass and code execution in iLO2 firmware 2.29CriticalFeb 15, 2018
Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who canCriticalDec 22, 2017- Intel Active Management Technology / Standard Manageability: An authentication bypass in the AMT web interface: sendingCriticalMay 2, 2017
Schneider Electric StruxureWare Data Center Expert before 7.4.0: Passwords held in cleartext in RAM on the DCIMMediumApr 30, 2017- Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) framework: Log into the Niagara platform with a disabled account nameCritical2017
- HTCondor (condor_schedd, GSI/VOMS extension parsing): An authenticated user crashes the schedd by feeding it malformedMedium2017
- SPI flash configuration (flash descriptor / protected range registers) across multiple Intel platformsMedium2017