Database/Control plane, storage & DevOps
Control plane, storage and DevOps vulnerabilities
Cluster management, storage systems, CI/CD, and observability tooling: GitLab, Harbor, Grafana, MinIO, Ceph, and the operator-facing services that hold the keys to a GPU fleet.
1,050 entries259 critical98 known exploitedFilter and search this layer
2026437
- Citrix NetScaler ADC/Gateway: Unauthenticated remote denial of service, actively exploitedHighOct 4, 2026
- Nx @nx/docker: config-controlled shell injection in release commands executes code in the release jobHighOct 2, 2026
- Trivy: Terraform filesystem functions read paths above the scan root during misconfig scansLowOct 2, 2026
- Fortra BoKS Manager: command injection in crlserver gives root on the BoKS Master via a crafted CRL URLCriticalOct 1, 2026
- Foreman: command injection in the errors:fetch_log rake task escalates a scoped sudo grant to full code executionHighOct 1, 2026
- Foreman / Red Hat Satellite: shell injection via foreman-rake db:dump and db:import_dump pathsHighOct 1, 2026
- Confluent Kafka Python client: TLS certificate verification disabled by default toward HashiCorp Vault KMSHighOct 1, 2026
- Pandora FMS: blind SQL injection through the module parameter of the Grafana datasource endpointHighOct 1, 2026
- Fortra BoKS Manager: oversized digest name in a KSL start message overflows a fixed 16-byte checksum fieldMediumOct 1, 2026
- ansible-runner: streamed archive extraction follows symlinks and writes outside the target directoryMediumOct 1, 2026
- Grafana: an Editor can mark a dashboard file-provisioned, making it undeletable by adminsMediumSep 30, 2026
- Grafana: alert rules API returns rules from folders the user cannot readMediumSep 30, 2026
- GitLab: stored XSS through merge request diff paths runs script in another user's sessionHighSep 29, 2026
HPE OneView: remotely exploitable session hijacking against the infrastructure management consoleHighSep 29, 2026
HPE OneView: remotely triggerable URL redirect in the management consoleMediumSep 29, 2026- GitLab: unauthenticated GraphQL requests can read CI/CD job traces containing secret variable valuesLowSep 29, 2026
- Citrix NetScaler ADC/Gateway: unauthenticated attacker executes arbitrary commands on the applianceCriticalSep 27, 2026
- Citrix NetScaler ADC/Gateway: unauthenticated remote code execution or denial of serviceCriticalSep 27, 2026
- OpenStack glance_store: VMware datastore driver sends authentication headers to an attacker-supplied image location hostHighSep 25, 2026
- RabbitMQ: super-stream binding-keys parsed before the permission check, one PUT kills the nodeHighSep 25, 2026
- MinIO: unsigned x-amz-copy-source on a presigned PUT URL turns one-object write into a read of any objectHighSep 25, 2026
- GitLab CE/EE: double free parsing a crafted CI/CD regular expression gives code execution on the serverCriticalSep 24, 2026
- GitLab CE/EE: integer overflow compiling a crafted CI/CD regular expression gives code execution on the serverCriticalSep 24, 2026
- GitLab EE: Duo AI troubleshooting exposes CI/CD variable values from debug job tracesHighSep 24, 2026
- Airflow HashiCorp provider: path-shaped Variable key crosses team scope in the Vault secrets backendMediumSep 24, 2026
- GitLab: MCP-scoped tokens can act beyond their intended scopeMediumSep 24, 2026
- Ansible automation-controller: copied workflows keep instance groups, letting a tenant run jobs on the control planeCriticalSep 23, 2026
- Ansible automation-controller: survey length-validation error leaks a stored password in plaintextHighSep 23, 2026
- Red Hat Ansible Automation Platform automation-controller (custom Credential Type env injector): The custom CredentialHighSep 23, 2026
- Ansible automation-controller: unvalidated system-job "days" value injects arguments into control-node awx-manageMediumSep 23, 2026
- Ansible automation-controller: Bitbucket DC webhook ping skips HMAC check, enumerating webhook-enabled templatesMediumSep 23, 2026
- Apache Airflow: Core API logout does not revoke bearer tokens, so a stolen token outlives the sessionCriticalSep 21, 2026
- Apache Airflow: /assets/events returns asset events for every DAG, ignoring per-DAG access controlMediumSep 21, 2026
- Apache Airflow 3.3.0-3.3.1: cookie wins over explicit bearer token, misattributing API calls and audit recordsMediumSep 21, 2026
- Grafana: symlink escape in plugin archive extraction gives remote code execution as the Grafana processHighSep 17, 2026
- Sidero Omni: Reader role can read the full CA secrets bundle of an imported Talos clusterHighSep 17, 2026
- Dell OpenManage Server Administrator (network-facing management service): OMSA is the in-band hardware management agentHighSep 17, 2026
- Sidero Omni: SAML assertion replay race lets a captured saml-session token be redeemed more than onceHighSep 17, 2026
- Dell OpenManage Server Administrator (authorization checks): A second, distinct flaw in the same OMSA versionsMediumSep 17, 2026
- Cisco ISE: unauthenticated API endpoint allows full authentication bypass on the applianceCriticalSep 16, 2026
- Airflow Keycloak provider: credentials of any confidential client in the realm log into AirflowCriticalSep 16, 2026
- Airflow FAB provider: password reset fails to evict existing sessions, so a stolen cookie keeps workingCriticalSep 16, 2026
- Airflow Keycloak provider: Keycloak tokens from unsigned cookies are not bound to the session identityCriticalSep 16, 2026
- Airflow FAB provider: password change through the Admin PATCH endpoint does not evict existing sessionsCriticalSep 16, 2026
- Airflow Kafka provider: connection editor gains code execution inside the scheduler processHighSep 16, 2026
- Jenkins Script Security Plugin: four Groovy sandbox escapes give code execution on the controllerHighSep 16, 2026
- Jenkins Robot Framework Plugin: archive path escapes the build directory, allowing arbitrary file writeHighSep 16, 2026
- GitLab EE: developer-level user can run a policy test pipeline and read protected CI/CD variablesHighSep 16, 2026
- Jenkins Script Security Plugin: @Builder builderStrategy escapes the Groovy sandboxHighSep 16, 2026
- GitLab CE/EE: unsanitized Markdown JSON table content induces state-changing requests as a targeted userHighSep 16, 2026
- Apache Airflow FAB provider: Authentik OAuth path does not check id_token issuer or audienceHighSep 16, 2026
- Jenkins Script Security Plugin (classpath entry approval): Script Security normally requires an administrator toHighSep 16, 2026
- Jenkins Warnings Plugin: unvalidated analysis results ID allows stored XSS in the controller UIHighSep 16, 2026
- Jenkins Coverage Plugin: unvalidated coverage results ID allows stored XSS in the controller UIHighSep 16, 2026
- Jenkins OWASP Dependency-Check Plugin: CWE values from reports are rendered unescaped, giving stored XSSHighSep 16, 2026
- Jenkins Script Security Plugin: approved JAR is re-downloaded, letting a second payload load into the controllerHighSep 16, 2026
- Jenkins Script Security Plugin: sandbox does not check dynamically added methods, allowing escapeHighSep 16, 2026
- Airflow FAB provider: deactivated accounts keep working through already-issued API tokensHighSep 16, 2026
- Harness: missing space-scoped access control lets any authenticated user read other spaces' infra provider configsHighSep 16, 2026
- GitLab CE/EE: Terraform state upload parameters let a project user read server files or DoS the instanceMediumSep 16, 2026
- Airflow Akeyless provider: path-shaped Variable key bypasses the team-scope guard on secret lookupMediumSep 16, 2026
- Jenkins Bitbucket Push and Pull Request Plugin: webhook payload can redirect credentialed requestsMediumSep 16, 2026
- GitLab: stored XSS via pasted HTML in the Content EditorMediumSep 16, 2026
- GitLab EE: Owner or Maintainer can silently disable protected-environment deployment approvalsMediumSep 16, 2026
- GitLab EE: Security Manager role can run arbitrary CI/CD jobs and read protected variablesMediumSep 16, 2026
- GitLab: developer-role user can replace package file content and hide packages from ownersMediumSep 16, 2026
- Woodpecker CI: pipeline authors can pick any ServiceAccount for their build podsCriticalSep 15, 2026
- OpenCost: unauthenticated POST /serviceKey overwrites the GCP service-account key fileHighSep 15, 2026
- GitLab EE: crafted project export import overflows the Advanced Search Unicode buffer for RCEHighSep 15, 2026
- Coder: workspace agent redirects let one tenant read, write and execute in another's workspaceHighSep 15, 2026
- GitLab CE/EE: environment scope matching lets an authenticated user read CI/CD variables outside their scopeHighSep 15, 2026
- Inspektor Gadget: crafted ld.so.cache in a container stalls the container-start hook cluster-wideMediumSep 15, 2026
- GitLab CE/EE: missing enforcement checks let an authenticated user bypass SAML SSO restrictionsMediumSep 15, 2026
- Strimzi: partial Entity Operator deployments still get both operators' RBAC, over-granting the SAMediumSep 15, 2026
- GitLab CE/EE: improper authorization on internal endpoints exposes credentials and tokensMediumSep 15, 2026
- Sealed Secrets controller: unauthenticated template oracle recovers sealed secret plaintextMediumSep 15, 2026
- Inspektor Gadget: malformed ELF crashes or exhausts memory in the privileged eBPF tracerLowSep 15, 2026
- Apache Storm worker-launcher: TOCTOU on the command file gives a tenant root-equivalent container launchHighSep 14, 2026
- OpenTelemetry Operator TargetAllocator: a tenant ServiceMonitor can exfiltrate the Collector's service-account tokenHighSep 14, 2026
- GitLab: unauthenticated arbitrary file read via the repository commits APICriticalSep 12, 2026
- GitLab EE: Duo Chat GraphQL subscription leaks Advanced Search config and credentialsCriticalSep 12, 2026
- Linux nfsd: async server-side COPY registers a stateid pointing into a reused request bufferCriticalSep 11, 2026
- Linux nfsd: filehandle composed from a stale dentry when dentry_create returns a different dentryCriticalSep 11, 2026
- Linux nfsd: pNFS layout fence worker takes a duplicate reference and leaks the layout stateidCriticalSep 11, 2026
- Linux nfsd: LAYOUTGET racing a delegation revoke hits a BUG_ON and panics the NFS serverCriticalSep 11, 2026
- Linux nfsd: seqid_op replay retry drops a stateowner reference it never tookCriticalSep 11, 2026
- Linux nfsd: session slot shrinker frees the slot in use, corrupting the slab with reply dataCriticalSep 11, 2026
- Linux nfsd: fh_verify tracepoints size the server address slot wrongly, writing past the trace bufferCriticalSep 11, 2026
- Linux nfsd: FREE_STATEID on an admin-revoked delegation leaves it on cl_revoked as freed memoryCriticalSep 11, 2026
- Linux nfsd: use-after-free on cl_cb_session when a session is destroyed with a callback in flightCriticalSep 11, 2026
- Linux kernel nfsd: module init error path leaves debugfs files pointing into freed module textHighSep 11, 2026
- Linux kernel nfsd: uncapped POSIX ACL entry count drives an O(n^2) sort in the NFS serverHighSep 11, 2026
- Linux kernel nfsd: crafted inter-server COPY compound reaches ops with a NULL filehandle and panics nfsdHighSep 11, 2026
- Linux kernel nfsd: unbounded symlink target length lets a client force multi-MiB kmallocs per COMPOUND opHighSep 11, 2026
- Linux kernel nfsd: async COPY samples the writeback error cursor late and reports failed copies as durableHighSep 11, 2026
- Linux kernel nfsd: write verifier not rotated when async COPY writeback fails, so COMMIT confirms lost dataHighSep 11, 2026
- Linux kernel nfsd: failed cross-mount leaks mount and dentry references on the NFS serverHighSep 11, 2026
- Linux kernel nfsd: stale opcnt after compound release leaks adjacent slab memory through the RPC status netlink dumpHighSep 11, 2026
- Linux kernel nfsd: dispatch error paths leave the status seqlock counter odd, exposing mutating compound stateHighSep 11, 2026
- OpenTelemetry eBPF Profiler: unprivileged process can stall the agent by mapping a FIFOMediumSep 11, 2026
- NVMe/TCP host: a short read is reported to userspace as a complete readUnscoredSep 11, 2026
- NVMe/TCP host: a malicious target can read host kernel memory by sending R2T for a READUnscoredSep 11, 2026
- NVMe/TCP host: C2HData for a WRITE_ZEROES command writes into a stale iteratorUnscoredSep 11, 2026
- Linux kernel nvme: discard fallback page is never zeroed, leaking kernel memory to the controllerUnscoredSep 11, 2026
- Linux CephFS client: leaked inode reference on aborted writeback panics the node at umountUnscoredSep 11, 2026
- Linux CephFS client: cap reclaim work busy-loops, burning CPU and contending dentry_list_lockUnscoredSep 11, 2026
- Linux CephFS client: unbounded delegated-inode intervals let a hostile MDS burn client CPU and memoryUnscoredSep 11, 2026
- Linux CephFS client: unchecked final xattr value length leaks kernel heap via getxattr(2)UnscoredSep 11, 2026
- Linux CephFS client: out-of-bounds read decoding MDS map info v2/v3 export targetsUnscoredSep 11, 2026
- Linux CephFS client: unbounded copy of MDSCapAuth path and fs_name crashes client at mountUnscoredSep 11, 2026
- Linux nfsd: use-after-free on an nfs4_client freed during NFSv4.0 revoked-state cleanupUnscoredSep 11, 2026
- Linux nfsd: use-after-free when a client is torn down while an expired delegation is being revokedUnscoredSep 11, 2026
- Linux nfsd: use-after-free on an nfs4_client freed while admin state revocation drops client_lockUnscoredSep 11, 2026
- Linux nfsd: writing unlock_filesystem after server shutdown walks freed state tables (use-after-free)UnscoredSep 11, 2026
- Linux nfsd: lock owner freed by the laundromat while client teardown walks it, causing a NULL dereferenceUnscoredSep 11, 2026
- Linux nfsd: copy-notify stateid freed while still discoverable, a use-after-free on all three revoke pathsUnscoredSep 11, 2026
- Linux nfsd: POSIX ACL refs leak on every malformed NFSv4 OPEN compoundUnscoredSep 11, 2026
- Linux nfsd: unvalidated NFSv3 nseconds corrupts on-disk timestamps on ext4 and XFSUnscoredSep 11, 2026
- Linux nfsd: copy-notify stateid published before initialisation, freeable by a racing OFFLOAD_CANCELUnscoredSep 11, 2026
- Linux nfsd: localio cmpxchg retry runs outside RCU, bumping a refcount on recycled memoryUnscoredSep 11, 2026
- Linux nfsd: NFSACL SETACL ignores the request mask and silently deletes the omitted ACLUnscoredSep 11, 2026
- Linux nfsd: flexfiles GETDEVICEINFO over-reserves da_addr_body and leaks reply-page memoryUnscoredSep 11, 2026
- Linux nfsd: flexfiles LAYOUTGET XDR size miscalculation writes past the reply bufferUnscoredSep 11, 2026
- Linux nfsd: use-after-free when OFFLOAD_CANCEL or shutdown races the async COPY kthreadUnscoredSep 11, 2026
- Renovate: unvalidated GitLab Link header redirects credential-bearing pagination requestsCriticalSep 10, 2026
- Renovate: unvalidated GitHub Link header sends host credentials to an attacker-controlled serverCriticalSep 10, 2026
- Renovate: NuGet datasource follows cross-origin Link pagination and leaks registry credentialsCriticalSep 10, 2026
- Renovate: Docker datasource follows cross-origin Link pagination and sends registry credentials to the attacker's hostCriticalSep 10, 2026
- Renovate: unescaped Gradle distributionUrl gives a repository command execution as the Renovate userHighSep 10, 2026
- Renovate: unescaped Maven Wrapper distributionType lets a repository run commands in the botHighSep 10, 2026
- Renovate: mutual-TLS private key written to logs in cleartext when it appears outside its own fieldHighSep 10, 2026
- Suricata: unbounded NFS parser state lets crafted traffic exhaust sensor memoryHighSep 10, 2026
- Renovate gomod manager: shell metacharacters in a dependency name run commands as the Renovate userHighSep 10, 2026
- Renovate Mix manager: unescaped organization parameter lets a package name run commands as the Renovate userHighSep 10, 2026
- Renovate: minimumReleaseAge is not applied to digest updates, so fresh dependency digests reach CI earlyMediumSep 10, 2026
- Ansible community.general: memcached fact cache unpickles values, giving code execution on the controllerHighSep 9, 2026
- Ansible community.general OCAPI modules: TLS verification disabled, enclosure credentials exposedMediumSep 9, 2026
Windows Services for NFS: use-after-free in the ONCRPC XDR driver allows unauthenticated remote code executionCriticalSep 8, 2026
Apache Airflow FAB provider: Azure AD id_token issuer and audience unchecked, any tenant can log inCriticalSep 8, 2026- MongoDB Server: use-after-free in query memory tracking crashes or corrupts the server processHighSep 8, 2026
- Dell Secure Connect Gateway: exposed Docker socket gives a local user or container host rootCriticalSep 7, 2026
- Jenkins: config.xml nested objects reachable via Stapler give authenticated users remote code executionHighSep 2, 2026
- Jenkins Stapler: form data binding instantiates configuration types the target field never expectedHighSep 2, 2026
- Jenkins: unescaped system log metadata lets an agent-controlled process store XSS in the controller UIHighSep 2, 2026
- Jenkins Stapler: CSRF crumb embedded in generated JavaScript leaks to same-site attackersHighSep 2, 2026
- Jenkins: transient fields cannot be excluded from deserialization of submitted configurationHighSep 2, 2026
- Jenkins SAML Plugin: IdP metadata file overwritable via data binding, allowing login as any userHighSep 2, 2026
- Jenkins Allure Plugin: path traversal lets Item/Read users read arbitrary controller filesHighSep 2, 2026
- Jenkins Performance Plugin: unsafe deserialization of cached reports gives Item/Configure users RCEHighSep 2, 2026
- Jenkins File Parameter Plugin: arbitrary file write on the controller via data binding leads to RCEHighSep 2, 2026
Jenkins Entra ID plugin: a colliding Entra group display name inherits a privileged group's permissionsHighSep 2, 2026- Jenkins Customizable Header Plugin: SVG icon config injection yields stored XSS on every pageHighSep 2, 2026
- Jenkins SonarQube Scanner Plugin: unrestricted URL scheme in dashboard links causes stored XSSHighSep 2, 2026
- Jenkins TICS plugin: attacker-controlled build variables execute arbitrary commands on the build agentHighSep 2, 2026
- Jenkins: session is not rotated on remember-me login, allowing session fixation against any userHighSep 2, 2026
- Grafana: Auth Proxy cache key collision authenticates a low-privileged user as an administratorHighSep 2, 2026
- Jenkins ThinBackup plugin: attacker redirects backups and pulls arbitrary controller files into themHighSep 2, 2026
- Grafana Enterprise: SAML responses skip InResponseTo validation, allowing assertion replayMediumSep 2, 2026
- Grafana: injected timeGroup macro in a SQL query exhausts memory and kills the server processMediumSep 2, 2026
- Jenkins: agent config update names its own target, letting one agent's configurer take over anotherMediumSep 2, 2026
- Jenkins Stapler: form binding writes public static fields, applying changes instance-wideMediumSep 2, 2026
- Jenkins Pipeline: Build Step Plugin: downstream builds cancelled without Item/Cancel permission checkMediumSep 2, 2026
- Jenkins Pipeline: Groovy Libraries plugin: CSRF lets an unauthenticated attacker delete library cachesMediumSep 2, 2026
- Jenkins GitLab plugin: global connection URL can be overwritten, sending admin API tokens to an attackerMediumSep 2, 2026
- Jenkins Job Configuration History Plugin: attackers redirect history storage to a directory of their choosingMediumSep 2, 2026
- Jenkins XL Deploy plugin: any user with Overall/Read can enumerate stored credential IDsMediumSep 2, 2026
- Jenkins update-center2: unescaped plugin metadata gives stored XSS on plugin download index pagesMediumSep 2, 2026
- Jenkins core: crafted XML submission lets a read-only user create user objects on the controllerMediumSep 2, 2026
- Jenkins core: unescaped map keys let a user inject arbitrary fields into JSON and Python API responsesMediumSep 2, 2026
- Jenkins core: missing permission check exposes build parameters of jobs a user cannot otherwise seeMediumSep 2, 2026
- Jenkins Script Security Plugin: form submission exposes the script approval configuration to attackersMediumSep 2, 2026
- Jenkins Script Security Plugin: missing permission check lets attackers disable global sandbox enforcementMediumSep 2, 2026
- Jenkins LDAP plugin: Stapler data binding lets a low-privileged user make the controller connect to any URLMediumSep 2, 2026
- Jenkins Parameterized Remote Trigger plugin: remote trigger tokens stored unencrypted in job config.xmlMediumSep 2, 2026
- Jenkins core: build CLI -s flag cancels other users' builds without the Item/Cancel permissionMediumSep 2, 2026
- Jenkins: Overall/Manage holders can change Appearance configuration reserved for administratorsLowSep 2, 2026
- SonicWall SMA1000: pre-auth SSRF via an unintended alternate access path in the Work Place interfaceCriticalSep 1, 2026
- OpenNebula: one.vm.exec skips the permission check, letting any user run commands in other tenants' VMsHighSep 1, 2026
LibreNMS: device hostname is concatenated into shell commands in libvirt discovery, giving RCEHighSep 1, 2026- SonicWall SMA1000: authenticated admin can inject OS commands through the management consoleHighSep 1, 2026
- AWX bulk job launch: read-level permission on an instance group is enough to run jobs on itMediumSep 1, 2026
- BOSH vSphere CPI: missing certificate pinning lets an interceptor impersonate vCenter and capture admin credentialsHighAug 29, 2026
- Ceph Monitor: any read-only CephX user can dump the config-key store, including cephadm's cluster-wide SSH keyCriticalAug 28, 2026
- Ceph RGW: unauthenticated STS token encryption lets any token holder bit-flip themselves to RGW adminHighAug 28, 2026
- Ceph RGW: unsigned x-amz-* headers on presigned URLs are honored, letting a URL holder escalate privilegesHighAug 28, 2026
- Grafana Alloy: ServiceMonitor bearerTokenFile reads any file and ships it to an attacker scrape targetHighAug 27, 2026
- Gitea: unauthenticated remote code execution via the diffpatch API installing Git hooksCriticalAug 26, 2026
- SeaweedFS S3 API: raw OIDC JWT bypasses IAM role trust policy and grants that role's bucket accessHighAug 26, 2026
- GitLab EE: developer-role user can run arbitrary commands in CI via attacker-controlled agent configHighAug 26, 2026
- GitLab CE/EE: authenticated user can stall background job processing via missing object count limitsMediumAug 26, 2026
- Grafana: org admin can delete other organizations' snapshots and recover delete keys from share keysMediumAug 26, 2026
- GitLab EE: project Maintainer can open a terminal on a protected environment they are not authorized forMediumAug 26, 2026
- community.general ipa_getkeytab: IPA/LDAP bind password written to logs and exposed in the process listMediumAug 26, 2026
- LibreNMS: reflected XSS in the Proxmox view runs script in a logged-in monitoring user's sessionMediumAug 26, 2026
- GitLab EE: developer-role user can influence the execution environment of Pipeline Execution Policy jobsMediumAug 26, 2026
- GitLab EE: reporter-role author of a merge request can reset its approval rulesLowAug 26, 2026
- galaxy_ng: namespace avatar URL is fetched unchecked, giving SSRF into internal and metadata endpointsMediumAug 25, 2026
- Ansible AWX: notification backends allow SSRF from the control node and leak webhook credentialsHighAug 24, 2026
- Grafana: unsanitized alert generatorURL runs attacker JavaScript in a viewing user's sessionMediumAug 24, 2026
- HashiCorp Vault: slash injection in templated policy paths grants access to unintended pathsMediumAug 24, 2026
- GitLab package registry: authenticated path traversal that can lead to remote code executionHighAug 23, 2026
- Netty: OpenSSL client path silently skips TLS hostname verification on Java 25+HighAug 22, 2026
- Linux kernel NFSv4 client: a delayed FREE_STATEID can use a freed nfs_serverUnscoredAug 22, 2026
Apache CloudStack: metalink template registration gives a tenant root on the KVM hypervisor hostHighAug 21, 2026- Atlantis: workspace names escape the working directory into os.RemoveAll and os.MkdirAllHighAug 21, 2026
- Terragrunt: malicious module manifest deletes files outside the module cache during cleanupMediumAug 21, 2026
- Apache CloudStack: unsanitized backup repository options inject OS commands onto the KVM hypervisor hostUnscoredAug 21, 2026
- OSNEXUS QuantaStor: unauthenticated Kapacitor access gives remote code execution as root on the storage nodeCriticalAug 20, 2026
- CloudNativePG: a database owner escalates to PostgreSQL superuser and OS command execution in the podCriticalAug 20, 2026
- Termix: any authenticated user can read other users' stored SSH and sudo passwordsCriticalAug 19, 2026
- Citrix NetScaler ADC and Gateway: unauthenticated remote compromise of the applianceCriticalAug 19, 2026
- Renovate (kustomize manager): chart names are injected into helm pull commands, running attacker shell commandsHighAug 19, 2026
- Renovate (helmv3 manager): repository value from Chart.yaml is injected into helm registry login commandsHighAug 19, 2026
IBM AIX and PowerVM VIOS: improper authentication allows remote access to NFS exportsHighAug 19, 2026- Splunk Enterprise Edge Processor sidecar: Prometheus metrics endpoint served without authenticationHighAug 19, 2026
- Dell OpenManage Enterprise: unauthenticated SSRF reaches services on the management networkHighAug 19, 2026
- Dell OpenManage Enterprise: privileged user can inject OS commands and run code on the applianceHighAug 19, 2026
- Dell OpenManage Enterprise: improper privilege management lets a privileged account escalate furtherHighAug 19, 2026
- Grafana: alert rule marked as a server-side expression bypasses datasource query authorizationHighAug 19, 2026
- Renovate self-hosted: child processes inherit the full environment, exposing every secretMediumAug 19, 2026
- HashiCorp go-slug: Unicode normalization mismatch lets excluded files slip past .terraformignore into the uploadMediumAug 19, 2026
- AAP Controller: testing a Vault credential sends the controller pod's service account token to an attacker URLCriticalAug 18, 2026
- Red Hat ACM: ManagedClusterAddOn annotation overrides governance-policy image, giving cluster-admin execHighAug 18, 2026
- Dell PowerStore T SDNAS: unauthenticated NFS/RPC buffer overflow allows command execution on the arrayHighAug 18, 2026
- Linuxfabrik monitoring plugins: pipe injection in shell_exec escalates a check account to rootHighAug 18, 2026
- Linuxfabrik monitoring plugins: sudo-authorized checks read arbitrary root-readable files via --testMediumAug 18, 2026
- Linuxfabrik monitoring plugins: symlink attack on predictable /tmp SQLite caches lets a local user write as rootLowAug 18, 2026
- GitLab: an unauthenticated GraphQL directive can modify or delete public projects and user dataCriticalAug 17, 2026
- GitLab: unauthenticated GraphQL mutations executed via GET through multiplex query handlingHighAug 17, 2026
- JumpServer: Jinja2 injection in Applet Host fields executes commands on the control nodeMediumAug 17, 2026
- Grafana: Org Admin can read dashboard permission mappings belonging to other organizationsMediumAug 17, 2026
Linux crypto driver for Marvell OCTEON TX: The scatter-gather cleanup path in the Marvell OCTEON TX crypto driver usesCriticalAug 15, 2026- Linux VXLAN driver (neighbour hardware address read in route_shortcircuit): `route_shortcircuit()` reads a neighbour'sCriticalAug 15, 2026
- Linux VXLAN driver (transmit-path header pulls): `vxlan_xmit()`, `arp_reduce()` and `vxlan_mdb_entry_skb_get()`CriticalAug 15, 2026
Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table): The LiquidIO PF caches VF `pci_dev` pointersCriticalAug 15, 2026
Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler): The OCTEON CN10K admin-function mailbox handlerHighAug 15, 2026- Linux octeontx2-af (VF clobbering shared CGX PKIND state): PF and VF NIX logical functions that share a CGX MAC reuseHighAug 15, 2026
- Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): A VF setting its receive mode causes the *physicalHighAug 15, 2026
- Linux perf/x86/amd/core - Branch Sampling enabled from the SVM reload path: Branch Sampling and Last Branch RecordUnscoredAug 15, 2026
- Vault Secrets Operator: tenant-controlled AppRole config reads operator pod files and exfiltrates themCriticalAug 13, 2026
Sigstore Fulcio: OIDC discovery follows cross-host redirects and leaks ServiceAccount tokensHighAug 13, 2026- OpenChoreo Backstage backend: hardcoded auth bypass exposes /api/* to unauthenticated callersHighAug 13, 2026
- rsync SSL modes: server TLS certificates are not validated, so an on-path attacker can read the transferHighAug 13, 2026
IBM Storage Scale GUI (hardcoded inter-node token): A hardcoded token in the Storage Scale GUI source, usedHighAug 13, 2026- PostgreSQL pgcrypto: PGP functions emit recoverable cleartext when OpenSSL disables the cipherMediumAug 13, 2026
- OpenChoreo: autobuild webhook picks its provider from a caller-supplied header and accepts unsigned Bitbucket requestsMediumAug 13, 2026
- Prowler: legacy gcp auth-provider in kubeconfig runs commands on the shared scan workerCriticalAug 12, 2026
- GitLab: unsanitized HTML in the CI job modal lets a developer-role user escalate privilegesCriticalAug 12, 2026
- Apache Airflow: executor_config deserialization imports arbitrary callables in scheduler and API serverHighAug 12, 2026
- Apache Airflow: Callback deserialization in the scheduler timeout sweep imports Dag-author-chosen modulesHighAug 12, 2026
- Linux VXLAN driver (CAP_NET_ADMIN check on changelink across netns): A VXLAN tunnel's `changelink()` operates acrossHighAug 12, 2026
- GitLab CE/EE: stored XSS in analytics dashboard pagination controlsHighAug 12, 2026
- GitLab CE/EE: stored XSS in analytics dashboard table cell renderingHighAug 12, 2026
- GitLab: developer-role user can run pipelines on a protected branch without push rightsHighAug 12, 2026
- GitLab EE: authenticated user can attribute AI usage to another namespaceHighAug 12, 2026
- JFrog Artifactory: internal anonymous-user token returned to unauthenticated callersHighAug 12, 2026
- Airflow Backfill API: any Dag editor can read and cancel backfills belonging to other DagsHighAug 12, 2026
- GitLab CE/EE: improper input validation lets an unauthenticated user cause a denial of serviceHighAug 12, 2026
- Apache Airflow 3.3.0: Dag author reaches arbitrary imports in the scheduler via next_kwargs deserializationHighAug 12, 2026
- GitLab EE: missing authorization lets a low-privileged member change restricted project settingsHighAug 12, 2026
- open-iscsi iscsiuio (DHCPv6 handling): Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handlingMediumAug 12, 2026
- Apache Airflow: JSON Variable secrets shown in cleartext in the Rendered Templates viewMediumAug 12, 2026
- Apache Airflow: masker misses team-prefixed config sections, exposing team Celery broker URLs with credentialsMediumAug 12, 2026
- Airflow Google provider: team scope dropped in Secret Manager backend, so one team resolves another's credentialsMediumAug 12, 2026
- Airflow: bulk Variable and Connection endpoints write secrets to the audit log in cleartextMediumAug 12, 2026
- Airflow Task SDK: Variables whose JSON value is a list are not masked in task logs or rendered templatesMediumAug 12, 2026
- Airflow: asset materialization authorizes the Dag without its team, letting one team trigger another's runsMediumAug 12, 2026
- GitLab EE: authenticated user can view restricted group configuration settingsMediumAug 12, 2026
- GitLab EE: GraphQL query exposes policy configuration from an unauthorized namespaceMediumAug 12, 2026
- GitLab EE: developer-role user can read external status check configuration for a merge requestMediumAug 12, 2026
- GitLab EE: authenticated user bypasses IP access restrictions to read private merge request dataMediumAug 12, 2026
- GitLab CE/EE: developer-role user can modify package registry metadata without maintainer rightsMediumAug 12, 2026
Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+): Three heap-basedCriticalAug 11, 2026- Grafana MCP Server: caller-controlled X-Grafana-URL header turns grafana_api_request into a full SSRF primitiveCriticalAug 11, 2026
- Apache Airflow Yandex provider (Lockbox secrets backend, team-scope lookup): When the team-scoped lookup for aMediumAug 10, 2026
- Airflow Amazon provider: AWS secrets backends fall through to a team-agnostic lookup, leaking other teams' credentialsMediumAug 10, 2026
- Linux iommu/amd - IRQ-unsafe locking in guest domain allocation: An IRQ-unsafe lock taken during AMD IOMMU guest domainUnscoredAug 10, 2026
- Jenkins Remoting: JEP-200 deserialization filter bypassed via fallback class resolution on the controllerCriticalAug 5, 2026
- Jenkins Multijob Plugin: Groovy features skip Script Security, giving job configurers controller RCEHighAug 5, 2026
- Jenkins Multijob Plugin: CSRF lets an attacker run code in the Jenkins controller JVMHighAug 5, 2026
- Jenkins: inconsistent case handling in user and group names allows impersonation of other accountsHighAug 5, 2026
- Jenkins Ivy Report Plugin: XXE in Ivy report parsing gives an authenticated user file read on the controllerHighAug 5, 2026
- Keycloak: authenticated user can exhaust server memory via unbounded Prometheus metric labelsMediumAug 5, 2026
- OpenStack Swift: S3API does not strip X-Copy-From, allowing cross-tenant object readsMediumAug 5, 2026
- Jenkins: symlinks with empty names in agent tar archives write arbitrary files on the controllerMediumAug 5, 2026
- Jenkins: path traversal in file parameter names writes arbitrary files on the controller filesystemMediumAug 5, 2026
- Jenkins: project naming strategy config lets Overall/Manage holders instantiate admin-only typesLowAug 5, 2026
N-able N-central: Incomplete patch for CVE-2026-18556HighAug 2, 2026
N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverHighAug 1, 2026- Performance Co-Pilot: signed integer overflow in __pmGetPDU permanently blinds the collector daemonHighJul 30, 2026
- Logging operator: unescaped Flow CRD values inject Fluentd directives and run commands in the aggregatorCriticalJul 29, 2026
Airflow FAB provider: Azure AD login accepted unsigned ID tokens, allowing login as AdminCriticalJul 29, 2026- open-iscsi / open-isns - iscsiuio control socket authorization and iSNS record handling: Three related defectsHighJul 29, 2026
- JetBrains TeamCity: Deserialization in the agent polling protocolCriticalJul 27, 2026
- JFrog Artifactory: token scope not validated, allowing privilege escalation from any low-privileged tokenHighJul 27, 2026
Progress Kemp LoadMaster Multi Tenant: The Multi Tenant product line's REST API doesn't check whether a caller'sHighJul 27, 2026- Linux crypto/ccp - SNP initialization on ioctl(SNP_COMMIT): The ccp driver initialised SNP from the SNP_COMMIT ioctlUnscoredJul 25, 2026
- Linux x86/mm - broadcast TLB flush with PCID disabled: Booting with nopcid clears the PCID feature but broadcast TLBUnscoredJul 24, 2026
- ansible-core: git argument injection in ansible-galaxy collection install yields command executionHighJul 21, 2026
- Linux MACsec (replay protection at XPN lower-PN wrap): MACsec replay protection fails at the extended-packet-numberHighJul 19, 2026
- VMware Avi Load Balancer: authentication bypass grants network access to the Avi control planeCriticalJul 18, 2026
- VMware Avi Load Balancer: remote code execution on the Avi Controller control planeHighJul 18, 2026
- VMware Avi Load Balancer: authenticated user can inject and execute code on the ControllerHighJul 18, 2026
- VMware Avi Load Balancer: authenticated privilege escalation leading to remote code executionHighJul 18, 2026
- VMware Avi Load Balancer: directory traversal through weak file path validationHighJul 18, 2026
- VMware Avi Load Balancer: authorization bypass exposes part of the Avi Controller control planeHighJul 18, 2026
- VMware Avi Load Balancer: local user can escalate to root on the applianceHighJul 18, 2026
- Apache Airflow Git provider: SSH host-key verification disabled by default when cloning DAG bundlesHighJul 13, 2026
- Apache Airflow FAB provider: a DAG named 'DAGs' collides with the global all-DAGs permission and escalates privilegesHighJul 13, 2026
- Apache Airflow: Bulk Variables API skips key-based redaction, returning JSON variable secrets in cleartextMediumJul 7, 2026
- Apache Airflow: Config API exposes secrets-backend kwargs overrides unmasked, leaking Vault credentialsMediumJul 7, 2026
- Apache Airflow: Dag source endpoint returns the whole file, exposing co-located Dags the caller cannot readMediumJul 7, 2026
- Apache Airflow: task-instance API returns deferred trigger kwargs unmasked, exposing secrets passed to triggersMediumJul 7, 2026
- Citrix NetScaler ADC/Gateway: memory overflow in Gateway and AAA vservers causes denial of serviceHighJun 30, 2026
- Kestra: suffix-match auth bypass on /configs gives unauthenticated workflow execution as rootCriticalJun 26, 2026
- Airflow FTP provider: FTPS data channel sent in cleartext because PROT P was never issuedHighJun 26, 2026
- Linux iommu/amd - devid bounds check in __rlookup_amd_iommu(): The AMD IOMMU driver looked up device IDs withoutMediumJun 26, 2026
- Jenkins Script Security Plugin: Groovy sandbox escape via AST annotation extensions memberHighJun 24, 2026
ATEN Unizon fleet management platform: Unizon is ATEN's centralized manager for its KVM and PDU fleet. The restoreDBHighJun 24, 2026- Linux kernel CephFS client: stale xattr blob size hits a BUG_ON and panics the nodeMediumJun 24, 2026
- Linux amd-pstate - memory leak in amd_pstate_epp_cpu_init(): On failure to set the energy-performance preferenceMediumJun 24, 2026
- Backpropagate (single-GPU LLM fine-tuning library) - Reflex web UI: The optional web UI exposes a training controlCriticalJun 17, 2026
- Jenkins: attacker-controlled config.xml deserialization allows user impersonation and code executionHighJun 10, 2026
- ansible.posix authorized_key: a symlink under a user's ~/.ssh redirects a root chown to any pathHighJun 10, 2026
- Jenkins: post-login redirect accepts URLs with tab or newline between slashes, enabling phishingMediumJun 10, 2026
Ivanti Sentry: OS command injectionCriticalJun 9, 2026- Fortinet FortiSandbox: OS command injectionCriticalJun 9, 2026
lldpd (802.1Q VLAN tag stripping in lldpd_decode): lldpd strips 802.1Q VLAN tags by memmove-ing the frame payload fourMediumJun 9, 2026
Schneider Electric Data Center Expert - SOAP service endpoints: XML external entity processing on DCE SOAP endpointsMediumJun 9, 2026- ansible-core: malicious Galaxy role injects git flags to run code on the machine installing itHighJun 5, 2026
Progress LoadMaster (ADC): OS command injection in the APICriticalJun 4, 2026
CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching): Stack-based buffer overflow in BIRD's AS_PATH maskMediumJun 2, 2026- OpenTelemetry JS Prometheus exporter: a malformed request URI crashes the whole Node.js processHighMay 27, 2026
- Palo Alto PAN-OS: GlobalProtect portal/gateway auth bypassCriticalMay 13, 2026
Ivanti Endpoint Manager Mobile: Improper input validationHighMay 7, 2026- Palo Alto PAN-OS: Buffer overflow in the User-ID Captive PortalCriticalMay 6, 2026
- Linux iommu/vt-d (dev-IOTLB flush in scalable mode): The scalable-mode half of the device-IOTLB invalidation problem —MediumMay 6, 2026
- Linux iommu/vt-d (dev-IOTLB flush for passed-through PCIe devices): The Intel IOMMU driver skips device-IOTLBMediumMay 6, 2026
- Prometheus: Azure AD remote-write client secret served in plaintext from the /-/config endpointHighMay 4, 2026
- Prometheus: unvalidated snappy decoded length on /api/v1/read lets a small request exhaust server memoryHighMay 4, 2026
- Linux EDAC/mc - error path ordering in edac_mc_alloc(): When a private-data allocation fails in edac_mc_alloc()MediumApr 27, 2026
- Grafana: legacy correlation records can be read and permanently deleted across organizationsLowApr 15, 2026
- Fortinet FortiSandbox: OS command injection via crafted HTTP requestsCriticalApr 14, 2026
- Apache Tomcat: Missing encryption of sensitive data introduced by the CVE-2026-29146 fixHighApr 9, 2026
- GitLab EE: missing namespace validation lets a user apply compliance frameworks from namespaces they cannot accessMediumApr 8, 2026
- Apache ActiveMQ: Improper input validation and code injection in the brokerHighApr 7, 2026
- Fortinet FortiClient EMS: Improper access controlCriticalApr 4, 2026
- Linux perf/x86 - event pointer setup ordering in x86_pmu_enable(): A NULL pointer dereference in the x86 PMU enableMediumApr 3, 2026
- Citrix NetScaler ADC/Gateway: Insufficient input validation as SAML IdPCriticalMar 23, 2026
- Elastic Metricbeat: oversized Prometheus remote_write request drives an unbounded allocation and kills the beatMediumMar 19, 2026
- Jenkins: symlinks in tar archives let a job or agent write files anywhere the controller canHighMar 18, 2026
- Cisco Secure Firewall Management Center: unauthenticated HTTP request yields root on the applianceCriticalMar 4, 2026
- Linux kernel CephFS client: invalid kfree() when listing .snap directories oopses the nodeMediumFeb 14, 2026
Ivanti Endpoint Manager (EPM): Auth bypass via alternate pathHighFeb 10, 2026- Fortinet FortiClient EMS: Unauthenticated SQL injectionCriticalFeb 6, 2026
Ivanti Endpoint Manager Mobile: Code injectionCriticalJan 29, 2026
Ivanti Endpoint Manager Mobile: Code injectionCriticalJan 29, 2026- Fortinet (FortiOS/FortiManager/FortiProxy): Auth bypass via alternate path using a FortiCloud account and a registeredCriticalJan 27, 2026
Kubeflow Pipelines frontend (/_proxy/ route, proxy-middleware.ts): The pipelines frontend hands any unauthenticatedCritical2026- Linux NFS server (nfsd, NFSv4.0 LOCK replay cache): A denied NFSv4.0 LOCK whose conflicting owner string is largeCritical2026
- rclone (rcd remote control server): An unauthenticated request to the rclone remote-control server instantiates aCritical2026
- Proxmox VE (libpve-storage-perl XXE): XML external entity injection in the Proxmox storage library, reachableCritical2026
- Linux NFS server (nfsd, SECINFO_NO_NAME decode): A truncated SECINFO_NO_NAME operation leaves sin_exp uninitialized andCritical2026
- VMware vCenter (VMware Directory Service authentication bypass): An unauthenticated attacker with network accessCritical2026
- VMware vCenter (Syslog server directory traversal to RCE): Directory traversal in the vCenter syslog server lettingCritical2026
- Linux SUNRPC (xdr_buf_to_bvec, nfsd write path): xdr_buf_to_bvec stores a bio_vec before checking the slot is in rangeCritical2026
- CloudNativePG instance manager (PostgreSQL connection search_path): The owner of any managed database — a roleCritical2026
- Assisted Migration Agent (hardcoded insecure TLS to vCenter): The agent hardcodes insecure TLS when talking to vCenterCritical2026
- MinIO (OIDC authentication): JWT algorithm confusion in the OIDC login path lets an attacker present a token the serverCritical2026
- rclone (rc API, options/set): options/set is exposed pre-authentication and can rewrite the running instance's authCritical2026
- rclone (rc API, operations/fsinfo): operations/fsinfo is reachable without authentication and accepts anCritical2026
- Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to ProxmoxCritical2026
- BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gateways: A runCritical2026
Crossplane package manager (cosign signature verification via ImageConfig): SUPPLY CHAIN, TIME-OF-CHECK TO TIME-OF-USECritical2026
Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole): The RHOAI overlayHigh2026- NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID): An attacker who already has valid credentialsHigh2026
- Supermicro SMASH service (X14DBG-DAP, X14DBI): An attacker with any authorised BMC login escalates through the SMASHHigh2026
- MinIO (S3 API, Snowball auto-extract): The Snowball auto-extract path skips signature verification entirely, so anHigh2026
- MinIO (S3 API, unsigned-trailer uploads): The signature on a query-string-credential unsigned-trailer upload is notHigh2026
- rclone (serve restic --private-repos): --private-repos is meant to confine each authenticated user to their ownHigh2026
- SkyPilot (API server, service account role update authorization): SkyPilot never checks whether the caller is entitledHigh2026
- KubeEdge (ConfigUpdateJob handler, updateFields): REMOTE CODE EXECUTION ON EDGE NODES via a normal Kubernetes APIHigh2026
- KubeEdge (NodeUpgradeJob handler, v1alpha2 API): REMOTE CODE EXECUTION ON EDGE NODES through the upgrade path. TheHigh2026
- Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64): An out-of-boundsHigh2026
- Pure Storage FlashArray Purity (data path information exposure): Insufficient filtering on certain data paths exposesHigh2026
- Pure Storage FlashArray Purity (management interface privilege bypass): An authenticated low-privileged user reachesHigh2026
- rclone (serve restic): Path validation in serve restic is incomplete, so an authenticated caller escapes the configuredHigh2026
- Pure Storage FlashBlade logging: Sensitive material ends up in FlashBlade logs under certain conditions, and the scoredHigh2026
- Ceph RGW (STS session tokens): Any tenant holding one ordinary STS session token can edit it into RGW superuser. RGWHigh2026
- CloudNativePG (role password handling, pg_stat_statements exposure): CREDENTIAL DISCLOSURE ACROSS THE TENANT BOUNDARYHigh2026
- Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodesHigh2026
- Cisco Intersight Device Connector for Nutanix Prism Central: The device connector exposes an unauthenticated APIHigh2026
- Ceph RGW (SigV4 signature verifier): Anyone handed a single presigned PUT URL gets more authority than whoever signedHigh2026
- Ceph MON (config-key store, MMonSubscribe handler): MULTI-TENANT ISOLATION AND HOST COMPROMISE: one craftedHigh2026
- VMware Aria Operations (command injection during assisted migration): An unauthenticated attacker injects commandsHigh2026
- MUNGE (munged credential daemon): This is the root of trust under Slurm. A crafted message with an oversizedHigh2026
- Dell OpenManage Server Administrator (improper authentication): An unauthenticated remote attacker gets unauthorizedHigh2026
- Automated Logic WebCTRL / i-Vu server and controllers, BACnet transport trust: This is the vendor formally concedingHigh2026
- rclone (local backend, --links): When rclone copies from an untrusted remote with --links, it recreates symlinksHigh2026
Sigstore cosign (verify-blob / verify-blob-attestation, legacy JSON bundle): SUPPLY CHAIN, VERIFICATION BYPASS: keylessHigh2026- MinIO (server-side encryption / replication): An authenticated tenant can inject SSE metadata through replicationHigh2026
- MinIO (S3 Select): A crafted S3 Select CSV query makes MinIO allocate memory without bound until the process isHigh2026
- Determined AI (master API, generic task kill/pause/unpause handlers): The generic task kill, pause and unpauseHigh2026
- Flux CD (allow-webhooks NetworkPolicy, notification-controller event server): CROSS-TENANT EVENT FORGERY: theHigh2026
- Volcano (admission webhook server, unbounded HTTP request body): The Volcano webhook server accepts request bodies ofMedium2026
- rclone (S3 backend, redirect sanitization): When rclone's S3 backend follows a redirect it strips some sensitiveMedium2026
- Dell OpenManage Server Administrator (relative path traversal): A low-privileged remote attacker reads arbitrary filesMedium2026
- rclone (serve s3): Path traversal in rclone's S3 gateway lets a caller read and overwrite files above the served root.Medium2026
- KubeEdge CloudHub (viaduct packer, pkg/viaduct/pkg/packer): ONE COMPROMISED EDGE NODE TAKES DOWN CLOUD-EDGEMedium2026
IBM Storage Scale management GUI (deploy and upgrade logging): The Storage Scale admin password is written in the clearMedium2026- Harbor (audit log redaction, LDAP password and OIDC client secret): CREDENTIAL DISCLOSURE VIA THE AUDIT TRAIL: HarborMedium2026
- CloudNativePG instance manager (status server, TCP/8000 control endpoints): A set of operator-only control endpointsMedium2026
DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls): Stack corruption inside the firmwareMedium2026
DMTF libspdm responder handling of GET_MEASUREMENT_EXTENSION_LOG: A requester reads memory it was never authorisedMedium2026- rclone (rc server, /debug/pprof handler): The pprof debug handler is mounted as its own route on the rcloneMedium2026
- NetApp ONTAP S3 NAS bucket directory listing: An authenticated S3 user lists the contents of directories they have noMedium2026
- SkyPilot (sky/users/server.py, user ID derivation from username): User IDs are derived with a weak hash of theLow2026
- QCT (Quanta Cloud Technology) server security centre: QCT firmware is unmeasurable from public data despiteUnscored2026
- Supermicro's public security advisory portal itself: An operator cannot programmatically track Supermicro firmwareUnscored2026
- Tyan / MiTAC Computing PSIRT: For Tyan, this vendor's firmware is unmeasurable from public dataUnscored2026
DMTF SPDM specification DSP0274 1.4 (FINISH transcript definition): A specification-level defect rather thanUnscored2026
DMTF libspdm (GET_MEASUREMENT_EXTENSION_LOG offset/length wrap): Wrapping addition of the Offset and Length fieldsUnscored2026- Linux Safe RET SRSO mitigation on AMD Zen 1-Zen 4 - interrupt-induced weakening: An attacker executing code on theUnscored2026
DMTF libspdm (cryptlib_mbedtls CSR generation, stack overflow): An over-long Common Name in a GET_CSR request writesUnscored2026- AMD - REP-string execution unit scheduler contention side channel: A newer variant of the SQUIP scheduler-contentionUnscored2026
Das U-Boot (FIT image signature verification): Binarly disclosed a cluster of flaws in U-Boot's FIT image handlingUnscored2026
WEKA Data Platform and VAST Data (published-advisory coverage): Neither WEKA nor VAST DataUnscored2026- BACnet / BACnet IP as a protocol (facility control plane): BACnet has no authentication, no integrity protection and noUnscored2026
NVMe-oF fabric authentication as deployed - host NQN allowlisting on Linux nvmet, SPDK and most storage appliancesUnscored2026- Landlord-owned facility control network in a leased colo or wholesale hall (governance gap): Almost every neocloudUnscored2026
- SES (SCSI Enclosure Services) enclosure management on shared SAS JBODs and expanders: SES is how a host controlsUnscored2026
- Modbus TCP as an unauthenticated control channel on facility gear: Modbus TCP has no authentication, no authorizationUnscored2026
- Wiegand reader-to-controller wiring and legacy 125 kHz proximity / MIFARE Classic credentials: Two structuralUnscored2026
- HTCondor (Access Point daemons, condor identity): A user with WRITE authorization on an Access Point - i.e. anyone whoUnscored2026
Kubeflow Pipelines (frontend server, /_proxy/ route in proxy-middleware.ts): The Kubeflow Pipelines frontend forwardsUnscored2026- HTCondor (Access Point daemons, condor identity): A user with WRITE authorization on an Access Point - i.e. anyone whoUnscored2026
Kubeflow Pipelines (frontend server, /_proxy/ route in proxy-middleware.ts): The Kubeflow Pipelines frontend forwardsUnscored2026
2025129
- GitLab: unauthenticated GraphQL requests exhaust resources through faulty complexity limitsHighSep 16, 2026
- Ceph CephX: malleable, unauthenticated tickets let a low-privilege key be forged into Manager, MDS or OSD accessHighAug 28, 2026
- GitLab EE: crafted SCIM provisioning input triggers an unbounded loop and takes the instance downMediumAug 26, 2026
- GitLab EE: pending members receive custom-role permissions before their membership is activeLowAug 12, 2026
- GitLab: a developer removed from a project can still push commits via merge request collaboration settingsLowJul 29, 2026
- GitLab: crafted Git ref names make the web UI show different content than the downloaded archiveMediumJul 8, 2026
- Arm Neoverse N1 / N2 / V1 / V2 / V3 / V3AE, Cortex-A76/A77/A78/A710, Cortex-X1-X925, C1-Ultra/PremiumCriticalJun 9, 2026
- AMD IOMMU register interface - ASP coherency: Improper access control on the IOMMU register interface lets a privilegedMediumJun 9, 2026
- AMD AGESA bootloader - DDR5 PMIC default configuration: The AGESA bootloader leaves DDR5 memory modules in an insecureMediumMay 15, 2026
- AMD NBIO register lock bits - System Management Network access: NBIO registers that should be locked after boot areHighMay 13, 2026
- AMD NBIO register lock bits - MMIO routing configuration: The sibling of the SMN issue: unprotected NBIO lock bits letMediumMay 13, 2026
- Apache CloudStack: MinIO policies survive bucket deletion, giving a former owner access to a new bucket of the same nameHighMay 8, 2026
- Grafana Alerting: Editor can exfiltrate contact point credentials by retargeting the test endpointLowApr 15, 2026
- Apache Airflow: pre-3.2 deployments lack the isolation guarantees operators assumed, per clarified security modelHighApr 13, 2026
- Apache Airflow: logout does not invalidate the session JWT, so an intercepted token stays usableCriticalApr 9, 2026
- Apache DolphinScheduler: exposed management endpoints leak database credentials to unauthenticated callersHighApr 9, 2026
- Ansible Automation Platform images: group-writable /etc/passwd lets a container user become root in-containerMediumApr 8, 2026
Lantronix EDS5000 serial-to-Ethernet device server: Root command execution on the device serverCriticalMar 11, 2026
Lantronix EDS3000PS serial-to-Ethernet device server: Full bypass of the management-page loginCriticalMar 11, 2026- rpc.mountd: NFSv3 client bypasses export restrictions and root_squash on subdirectoriesMediumMar 4, 2026
- AMD Graphics Driver - out-of-bounds write: Improper input validation lets a local attacker write out of bounds throughMediumFeb 11, 2026
- AMD - overlap between segmented reverse map table (RMP) and SMM memory: Improper handling of overlap between theMediumFeb 10, 2026
- Fortinet FortiOS and FortiSwitchManager: heap overflow in packet handling gives unauthenticated code executionCriticalJan 13, 2026
- Linux perf/x86/amd - general protection fault from a NULL event on enable: A subtle race lets cpucUnscoredJan 13, 2026
- MongoDB Server: Mismatched Zlib compressed header lengthsHighDec 19, 2025
- AMD Zen 5 RDSEED (16-bit and 32-bit variants): On Zen 5, the 16-bit and 32-bit forms of RDSEED return zero far moreHighDec 16, 2025
Sunbird Power IQ 9.2.0 API: Error-based SQL injection through an outdated API endpoint with missing input validationLowDec 15, 2025- AMD CPUs - attacker influence over RDSEED entropy: A local attacker can influence the values RDSEED returns, causingHighNov 21, 2025
Nagios XI: systemd unit files shipped with unnecessary executable permissionsMediumOct 30, 2025- Go crypto/x509 (Tailscale, Go infra): Name-constraint checking scales non-linearly with certificate sizeHighOct 29, 2025
- Oracle ZFS Storage Appliance Kit: HTTP-reachable flaw in Block Storage allows full appliance takeoverHighOct 21, 2025
- F5 BIG-IP (APM access policy): Specific malicious traffic against a virtual server with a BIG-IP APM access policyCriticalOct 15, 2025
- F5 BIG-IP (iHealth command / tmsh restricted shell): An authenticated attacker with at least a resource-administratorHighOct 15, 2025
- Linux iommu/amd - race while increasing host page table level: The AMD IOMMU host page table implementation supportsHighOct 9, 2025
- Juniper Security Director Policy Enforcer: unauthenticated attacker can replace vSRX images pushed to VMware NSXHighOct 9, 2025
- Redis: "RediShell" - authenticated user crafts a Lua script to trigger a use-after-freeCriticalOct 3, 2025
SPDK (Storage Performance Development Kit) 25.05 - NVMe-oF target, lib/nvmf: A buffer overflow in the NVMe-oF targetMediumOct 1, 2025
SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12): Rowhammer bit flips on DDR5, which had been assumed outHighSep 15, 2025- Citrix NetScaler: Memory overflowCriticalAug 26, 2025
- Linux x86/CPU/AMD - INVLPGB on Zen 2 (Cyan Skillfish): Using broadcast TLB invalidation (INVLPGB) on affected Zen 2MediumAug 16, 2025
N-able N-central: Improper input validationHighAug 14, 2025
N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM serverHighAug 14, 2025- Intel oneAPI toolkit and component installers: An uncontrolled library search path: the component loads a sharedMediumAug 12, 2025
- Intel oneAPI DPC++/C++ compiler installer: The compiler installer sets permissions that let a local user modifyMediumAug 12, 2025
- Intel oneAPI DPC++/C++ compiler: An uncontrolled library search path: the component loads a shared library by nameMediumAug 12, 2025
- HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault hostCriticalAug 1, 2025
OAuth2-Proxy: skip_auth_routes route matching flawCriticalJul 30, 2025
Lantronix Provisioning Manager: Provisioning Manager reads configuration files supplied by the network devicesHighJul 22, 2025- Fortinet FortiWeb: Unauthenticated SQL injectionCriticalJul 17, 2025
- Jenkins (Git Parameter plugin): Git parameter value is not validated against the offered choicesHighJul 9, 2025
Marvell QConvergeConsole (QLogic Fibre Channel / FC-NVMe / CNA HBA management web console), 5.5.0.78 and earlierCriticalJul 7, 2025- Redis: Authenticated user triggers a stack/heap out-of-bounds write in hyperloglog opsHighJul 7, 2025
- Citrix NetScaler ADC / Gateway (configured as VPN Gateway, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server): A memoryCriticalJun 25, 2025
- Kibana: Open redirect leading to SSRF via a specially crafted URLMediumJun 25, 2025
- Veeam Backup & Replication: Authenticated domain user achieves remote code execution on the Backup ServerHighJun 19, 2025
Teleport: Remote authentication bypass in Teleport Community Edition (<=17.5.1)CriticalJun 17, 2025- Citrix NetScaler ADC/Gateway: "CitrixBleed 2" - insufficient input validationHighJun 17, 2025
- Apache Kafka (client): SASL/OAUTHBEARER endpoint URLs accept file://HighJun 10, 2025
- AMD Versal Adaptive SoC - PLM runtime services address validation: The Platform Loader and Manager firmware on AMDMediumJun 10, 2025
- Cisco Nexus Dashboard Fabric Controller (SSH host key validation): NDFC does not validate the SSH host keysHighJun 4, 2025
- Grafana: Client path traversal + open redirectHighMay 22, 2025
- HashiCorp Nomad Enterprise: Jobs using the policy-override option bypass mandatory Sentinel policiesHighMay 13, 2025
- Intel E810 NVM Update Utility: Insecure inherited permissions in the NVM update utilityMediumMay 13, 2025
- OpenVINO Model Server: An unauthenticated request can drive OpenVINO Model Server into unbounded resource consumptionMediumMay 13, 2025
IBM Storage Scale (command input neutralization): An authenticated user can execute privileged commands due to improperHighMay 10, 2025
Arista CloudVision (Zero Touch Provisioning): Zero Touch Provisioning can be abused to obtain admin privilegesCriticalMay 8, 2025- HashiCorp Vault: KV v2 leaks sensitive payload content into server and audit logs on malformed requestsMediumMay 2, 2025
- Commvault Web Server: Remote authenticated attacker creates and executes webshellsHighApr 25, 2025
ConnectWise ScreenConnect: ViewState code injectionHighApr 25, 2025- Commvault Command Center: Unauthenticated ZIP upload + path traversalCriticalApr 22, 2025
- Linux cpufreq/amd-pstate - missing NULL check in amd_pstate_update: amd_pstate_update() dereferences the cpufreq policyMediumApr 16, 2025
Ivanti Connect Secure/ZTA: Stack-based buffer overflowCriticalApr 3, 2025- OpenVPN: Corrupting and replaying early-handshake packets against a tls-crypt-v2 serverHighApr 2, 2025
- Veeam Backup & Replication: Remote code execution reachable by any domain user on a domain-joined backup serverHighMar 20, 2025
- GitLab (ruby-saml): ReXML/Nokogiri parser differentialCriticalMar 12, 2025
- Linux cpufreq/amd-pstate - cpufreq_policy reference counting: amd_pstate_update_limits() takes a cpufreq_policyMediumMar 7, 2025
- Cisco Nexus 3000/9000 (health monitoring diagnostics): The health monitoring diagnostics subsystem on Nexus 3000 andHighFeb 26, 2025
- PostgreSQL (libpq): Improper quoting in PQescape*HighFeb 13, 2025
- Palo Alto PAN-OS: Management web interface auth bypass invoking PHP scriptsCriticalFeb 12, 2025
- Argo CD: Secret values exposed in error messages and the diff view when an invalid Secret is syncedMediumJan 30, 2025
- Linux platform/x86/amd/pmc - IRQ1 wakeup disabled unconditionally: The AMD PMC driver disabled IRQ1 wakeup in casesMediumJan 19, 2025
Ivanti Connect Secure: Stack-based buffer overflowCriticalJan 8, 2025- Deep Sea Electronics DSE855 generator communications gateway v1.1.0-v1.1.26 (realtime.cgi): Incorrect access controlCritical2025
HPE OneView (unauthenticated remote code execution): Unauthenticated remote code execution on OneView with scope changeCritical2025
HPE StoreOnce: unauthenticated command injection allows remote code execution on the backup applianceCritical2025
HPE StoreOnce (server-side request forgery): SSRF from the backup appliance, letting an unauthenticated attacker pivotCritical2025
HPE StoreOnce (authentication bypass): Unauthenticated attacker bypasses authentication on StoreOnce entirely, gainingCritical2025
HPE StoreOnce (directory traversal information disclosure): Unauthenticated directory traversal disclosing filesCritical2025- HPE Insight Remote Support (remote code execution): Unauthenticated remote code execution on the Insight RS serverCritical2025
- Linux NFS server (nfsd, nfsd4_spo_must_allow): nfsd4_spo_must_allow examines NFSv4 compound state without firstCritical2025
- Linux NFS server (nfsd, nfsd_set_fh_dentry): A refcount leak in the pseudo-root filehandle path lets a client drive theCritical2025
Vertiv (stack-based buffer overflow, code execution): A stack overflow gives an attacker code execution on the VertivCritical2025
Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cards: Authentication bypass plusCritical2025- Johnson Controls Metasys Application and Data Server (ADS) deployed with SQL Express: Command injection on the MetasysCritical2025
- Dell CloudLink (restricted shell breakout): A privileged user breaks out of the restricted shell into a full commandCritical2025
- Dell CloudLink (CLI escape): A privileged user with a known password escapes the CLI and takes control of the CloudLinkCritical2025
- Ceph CephX (authentication protocol): A tenant holding one low-privilege CephX client key ends up with cluster-wideHigh2025
- Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone Controller: Malformed BACnetHigh2025
- Dell OpenManage Network Integration (RADIUS auth bypass): An attacker on the local network forges a valid RADIUS AcceptHigh2025
- VMware vCenter Server (authenticated command execution via alarms): A user with permission to create or modify alarmsHigh2025
- MinIO (S3 API, unsigned-trailer uploads): Signature validation on unsigned-trailer uploads is incomplete, so knowingHigh2025
HPE OneView for VMware vCenter (vertical privilege escalation): A read-only user performs administrative actionsHigh2025- VMware Aria Operations for Logs (credential disclosure): A View Only Admin reads the credentials of other VMwareHigh2025
- VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissionsHigh2025
- Dell CloudLink (command injection): Command injection giving a privileged user full control of the CloudLink systemHigh2025
- Dell CloudLink (console command injection): Command injection from the console giving shell accessHigh2025
- Pure Storage FlashBlade authentication input validation: The FlashBlade equivalent of the FlashArray pre-authenticationHigh2025
- Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack bufferHigh2025
- VMware Aria Automation (DOM-based XSS, token theft): A crafted URL steals the access token of a logged-in AriaHigh2025
- OpenShift Hive / MCE / ACM (vCenter credential exposure): vCenter credentials are written into the ClusterProvisionHigh2025
HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUIHigh2025- HTCondor (IDToken authorization restrictions): The per-token authorization restrictions attached withHigh2025
- MinIO (service accounts / STS session policies): The session policy attached to a service account or STS credential isHigh2025
- Linux NFS server (nfsd, NFSv4 file creation ACL): When a client sets an ACL during NFSv4 file creation, nfsd silentlyHigh2025
- Tridium Niagara Framework and Niagara Enterprise Security (before 4.10.11 / 4.14.2 / 4.15.1): A chain, not a singleHigh2025
- HPE Insight Remote Support (unauthenticated denial of service): An unauthenticated attacker takes Insight RS downHigh2025
- HPE Insight Remote Support (path traversal): Unauthenticated path traversal disclosing files from the IRS serverHigh2025
- Volcano (scheduler, Elastic service and extender plugin response handling): The scheduler reads unbounded responsesHigh2025
- Redis (multi-bulk command protocol handling): PERMANENT, VENDOR-ACKNOWLEDGED DENIAL OF SERVICE WITH NO FIX PLANNED. AnHigh2025
- Motherboards from ASRock and its subsidiaries ASRockRack and ASRockInd built on Intel 500-series chipsetsMedium2025
- Dell CloudLink (privilege escalation to database): A privileged user escalates laterally or reads the CloudLinkMedium2025
- Dell CloudLink (risky cryptographic primitive): Use of a cryptographic primitive with a risky implementationMedium2025
IBM Storage Scale SMB protocol stack (inherited ACL handling): Files created or modified over SMB inherit permissionsMedium2025- CephFS (ceph-fuse client): A tenant with an ordinary unprivileged UID on a node that has a CephFS volume mounted viaMedium2025
- MinIO (SFTP gateway): The SFTP frontend trusts an SSH public key it should not, letting an attacker authenticate asMedium2025
Slurm (slurmdbd accounting, Coordinator role): A Coordinator - the delegated role a site gives a team lead over theirMedium2025- HTCondor (condor_schedd / Access Point): A user plants a specially crafted job that lies dormant, then runs as aMedium2025
- AMD Zen 3 / Zen 4 - new exploitation method for SRSO (CVE-2023-20569): Google's security team demonstrated a new way toUnscored2025
- AMD confidential computing - DDR5 memory bus interposition against TEEs: Compromising trusted execution environments byUnscored2025
2024137
- GitLab CE/EE: pipeline creation race lets a developer act in the context of another user's merge request commitMediumSep 16, 2026
- Renovate: shell metacharacters in helmv3 registryAliases give commit-access users command executionCriticalAug 19, 2026
- Dell OpenManage Integration for Windows Admin Center: authenticated remote code execution in the gateway pluginHighJun 16, 2026
- AMD Radeon RGB tool - signature verification on files in the installation directory: The Radeon RGB tool doesHighMay 15, 2026
- AMD PCIe link handling (memory buffer bounds): A guest VM can drive the PCIe link into an out-of-bounds conditionMediumFeb 13, 2026
- AMD Graphics Driver - crafted pointer leading to arbitrary code execution: Improper input validation in the AMDHighFeb 11, 2026
- AMD Graphics Driver - integer overflow bypassing size checks: An integer overflow in the AMD graphics driver letsMediumFeb 11, 2026
APC Network Management Card 4 (NMC4): An unauthenticated attacker can manipulate URL parameters to walk out of the webHighDec 11, 2025- GitLab CE/EE: authenticated user can obtain higher-privileged users' credentials and act as themMediumDec 5, 2025
- Nagios XI: Docker Wizard command injection gives admins code execution as the web userCriticalOct 30, 2025
- AMD Graphics Driver - crafted pointer leading to arbitrary writes: A specially crafted pointer passed to the AMDHighSep 6, 2025
- AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014): The BadRAM SPD-aliasing technique aimed atHighSep 6, 2025
- AMD Optimizing CPU Libraries (AOCL) - installation directory permissions: AOCL installs with permissive directoryHighMay 13, 2025
- Intel Data Center GPU Flex Series - Windows driver: Improper buffer restrictions in the Flex Series Windows driver letHighMay 13, 2025
- AMD Optimizing CPU Libraries (AOCL) - DLL hijacking: A DLL search-order hijack in AOCL lets an attacker getHighMay 13, 2025
- Intel Data Center GPU Flex Series - Windows driver: A further improper access control in the Flex Series Windows driverHighMay 13, 2025
- Intel oneAPI Level Zero software: An uncontrolled search path in Level Zero lets an authenticated local user get codeMediumMay 13, 2025
- Intel oneAPI DPC++/C++ compiler: An uncontrolled library search path: the component loads a shared library by nameMediumMay 13, 2025
- Intel Data Center GPU Flex Series - Windows driver software: Improper access control in the Flex Series Windows driverMediumMay 13, 2025
Arista CloudVision Portal (on-premise): An authenticated CloudVision user can take actions on managed EOS devices wellCriticalMay 8, 2025
NAKIVO Backup & Replication: Unauthenticated absolute path traversal via getImageByPathHighMar 4, 2025- Fluent Bit: Prometheus Remote Write input crashes on a Content-Length: 0 packetHighFeb 18, 2025
- Fluent Bit: OpenTelemetry input plugin crashes on a Content-Length: 0 packetHighFeb 18, 2025
- AmdCpmDisplayFeatureSMM - SMM callout (AMD-SB-7027): An SMM callout in the AmdCpmDisplayFeatureSMM driver lets ring-0HighFeb 11, 2025
- AmdPlatformRasSspSmm - SMM callout (AMD-SB-7028): An SMM callout in the platform RAS SMM driver lets ring-0 code modifyHighFeb 11, 2025
- AmdPspP2CmboxV2 - SMM input validation (AMD-SB-7027): Insufficient input validation in the AmdPspP2CmboxV2 SMM driverHighFeb 11, 2025
CyberPower PowerPanel Business 4.11.0 - Service Watchdog on TCP/2003: An unauthenticated attacker can repeatedlyHighJan 15, 2025- Fortinet FortiOS/FortiProxy: Auth bypass via crafted Node.js websocket requestsCriticalJan 14, 2025
- Redis: Malformed ACL selector triggers a server panicMediumJan 6, 2025
IBM Storage Scale GUI (local privilege escalation): A local privilege escalation in the Storage Scale GUI availableHighDec 14, 2024- Arm Neoverse V1 / V2 / V3 / V3AE / N2 and Cortex-A77/A78/A710/X1-X925 cores with Hardware Page Aggregation enabledCriticalDec 10, 2024
Digi ConnectPort LTS (before 1.4.12): An attacker who can reach the ConnectPort LTS's file-upload featureHighDec 9, 2024
Zabbix: SQL injection in CUser::addRelatedObjects reachable by ANY non-admin account with API accessCriticalNov 27, 2024- Keycloak: Regex complexity in SearchQueryUtilsMediumNov 25, 2024
- Apache Kafka (client): ConfigProvider plugins let an untrusted app read files/env of the Kafka client hostMediumNov 19, 2024
- Palo Alto PAN-OS: Management web interface authentication bypassCriticalNov 18, 2024
- Palo Alto PAN-OS: Admin with mgmt-interface access performs firewall actions as rootHighNov 18, 2024
- PostgreSQL: PL/Perl lets an unprivileged DB user change process env vars (e.g. PATH)HighNov 14, 2024
- Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural CompressorHighNov 13, 2024
- Intel Neural Compressor: Unauthenticated input-validation failure leading to escalation of privilege in NeuralHighNov 13, 2024
- Intel Neural Compressor (SQL injection, second instance): A second SQL-injection path in Neural Compressor reachableHighNov 13, 2024
- Intel Distribution of OpenVINO Model Server: An unauthenticated user can reach an input-validation flaw in OpenVINOMediumNov 13, 2024
- Intel Neural Compressor: Input-validation failure reachable by an authenticated user, ending in privilege escalationMediumNov 13, 2024
- Prometheus / Thanos (golang-jwt): Unclear ParseWithClaims error behaviorLowNov 4, 2024
- HashiCorp Consul: Missing Content-Type header lets user input be reinterpretedMediumOct 30, 2024
- Fortinet FortiManager: "FortiJump" - missing authentication in fgfmdCriticalOct 23, 2024
- Linux cpufreq/amd-pstate - unchecked cpufreq_cpu_get() return value: cpufreq_cpu_get() can return NULL and amd-pstateMediumOct 21, 2024
- Grafana: SQL Expressions passes user input to duckdb unsanitizedCriticalOct 18, 2024
Schneider Electric Data Center Expert - upgrade bundle signature verification: Improper cryptographic signatureHighOct 11, 2024- GitHub Enterprise Server: Improper signature verificationCriticalOct 10, 2024
- HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policyHighOct 10, 2024
- Cisco Nexus Dashboard Fabric Controller (REST API / web UI): A low-privileged NDFC userCriticalOct 2, 2024
- Keycloak: SAML signature scope determined by position, not ReferenceHighSep 19, 2024
- Linux HID/amd_sfh - driver_data freed after HID device destruction: A use-after-free in the AMD Sensor Fusion Hub HIDHighSep 18, 2024
- GitLab (ruby-saml): Ruby-SAML does not properly verify the SAML Response signatureCriticalSep 10, 2024
- Veeam Backup & Replication: Deserialization of untrusted dataCriticalSep 7, 2024
Progress Kemp LoadMaster (including Multi-Tenancy edition): A request handler fails to validate its input beforeCriticalSep 5, 2024
Infineon cryptographic library (ECDSA) in security microcontrollers: Electromagnetic side channel in Infineon's ECDSAMediumSep 3, 2024- GitHub Enterprise Server: XML signature wrapping with publicly exposed federation metadataCriticalAug 20, 2024
- Intel oneAPI compiler: An uncontrolled library search path: the component loads a shared library by nameMediumAug 14, 2024
- Intel Data Center GPU Max Series 1100 / 1550: A second improper conditions check in the Max Series allowingMediumAug 14, 2024
- Kibana: Prototype pollution via ML/Alerting connectors + write access to internal ML indicesCriticalAug 13, 2024
- PostgreSQL: TOCTOU race in pg_dumpHighAug 8, 2024
- Jenkins: Agent processes can read arbitrary controller files via ClassLoaderProxy#fetchJarHighAug 7, 2024
- Gitea: Stored cross-site scripting in Gitea 1.22.0CriticalAug 6, 2024
- Elasticsearch: elasticsearch-certutil --csr writes the private key to disk unencrypted despite --passMediumJul 31, 2024
- Linux cpufreq/amd-pstate - memory leak on CPU EPP exit: The amd-pstate driver leaks its per-CPU allocation when a CPU'sMediumJul 12, 2024
- GitLab: Attacker can trigger a CI pipeline as another userCriticalJul 11, 2024
OpenVPN (tap-windows6): Unchecked write sizeCriticalJul 8, 2024- OpenVPN: Stack overflow in the interactive serviceHighJul 8, 2024
- OpenVPN: The interactive service pipe is reachable remotelyHighJul 8, 2024
A10 Thunder ADC (CsrRequestView): An authenticated attacker can inject a system-call payload through the CsrRequestViewHighJun 6, 2024- OpenTelemetry Collector: Unsafe decompressionHighJun 5, 2024
- Veeam Backup Enterprise Manager: Unauthenticated users can log in as any user to the Enterprise Manager web interfaceCriticalMay 22, 2024
- Fluent Bit: "Linguistic Lumberjack" - memory corruption parsing trace requests in the embedded HTTP serverCriticalMay 20, 2024
- GitHub Enterprise Server: Forged SAML response with encrypted assertions enabledCriticalMay 20, 2024
Zabbix: Unsanitized clientip in the audit logCriticalMay 17, 2024- Intel Neural Compressor: An unauthenticated user can reach an input-validation failure in Neural CompressorCriticalMay 16, 2024
- Sonatype Nexus Repository 3: Unauthenticated path traversalHighMay 16, 2024
- Intel Neural Compressor (TOCTOU): A time-of-check/time-of-use race in Neural Compressor lets an authenticated localMediumMay 16, 2024
CyberPower PowerPanel platform - hardcoded database, service and cloud credentials: Hardcoded credentials usedCriticalMay 15, 2024
CyberPower PowerPanel business application - JWT signing key: The JWT signing key is hardcoded in the application, soCriticalMay 15, 2024
CyberPower PowerPanel business application - hardcoded authentication credentials: A hardcoded credential set compiledCriticalMay 15, 2024
CyberPower PowerPanel MQTT message handling: An attacker with MQTT publish permissions can craft messagesHighMay 15, 2024
CyberPower PowerPanel managed devices - shared device certificates: Every managed device uses an identical certificateHighMay 15, 2024
CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIs: Certain utility REST APIs have no authenticationCriticalMay 14, 2024- Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0a: Three defects that together mean every SANnav OVAHighApr 19, 2024
- Terraform (go-getter): Argument injection when go-getter shells out to Git for remote branch discoveryCriticalApr 17, 2024
- Palo Alto PAN-OS: GlobalProtect arbitrary file creationCriticalApr 12, 2024
- Linux nfsd (NFS server): Broken RELEASE_LOCKOWNER handling in nfsd causing state corruptionMediumMar 13, 2024
Moxa NPort W2150A / W2250A wireless device server: A remote attacker can crash or potentially gain code executionHighMar 6, 2024- JetBrains TeamCity: Alternative-path authentication bypassCriticalMar 4, 2024
ConnectWise ScreenConnect: Auth bypass via alternate pathCriticalFeb 21, 2024
ConnectWise ScreenConnect: Path traversal enabling remote code executionHighFeb 21, 2024- Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode): SR670 V2 servers built between roughly June 2021 and JulyLowFeb 16, 2024
- Fortinet FortiOS: SSL-VPN out-of-bounds writeCriticalFeb 9, 2024
- MinIO: Access keys inherit the parent's `admin:*` actions, not just `s3:*`HighJan 31, 2024
- Jenkins: CLI parser expands `@file` into argument contentsCriticalJan 24, 2024
- Jenkins: No origin validation on the CLI WebSocket endpointHighJan 24, 2024
Ivanti Connect Secure: Command injection in web componentsCriticalJan 12, 2024- Pure Storage FlashArray Purity (dormant configuration account): A local account intended only for initial arrayCritical2024
- Pure Storage FlashArray Purity (privileged remote access account): An attacker uses a privileged account to gain remoteCritical2024
- Automated Logic WebCTRL 7.0 / WebCTRL Premium Server / Carrier i-Vu building automation server: Unauthenticated fileCritical2024
- NetApp ONTAP Select Deploy administration utility (hard-coded credentials): Baked-in credentials let an attacker readCritical2024
HPE Cray Parallel Application Launch Service (PALS) authentication bypass: Authentication bypass in the serviceCritical2024- LenelS2 NetBox access control and event monitoring system (<=5.6.1): Unauthenticated remote code executionCritical2024
- Volcano (v1.8.2 and earlier, service account token permissions): Volcano 1.8.2 ships over-permissive settings that letCritical2024
- VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticatedCritical2024
- Linux NFS server (nfsd, laundromat vs free_stateid race): A race between the delegation laundromat and a client-issuedCritical2024
- HPE Insight Remote Support (directory traversal to RCE): Directory traversal allowing unauthenticated remote codeCritical2024
- MinIO (admin IAM import API): The IAM import API can be driven to grant an attacker administrative policy, converting aCritical2024
- Pure Storage FlashArray Purity (remote administrative account creation): An attacker uses a remote administrativeCritical2024
- Pure Storage FlashArray Purity (array admin command execution): A user holding the array admin role executes arbitraryCritical2024
- Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection): A crafted SNMP configuration yieldsCritical2024
- Linux NFS server (nfsd, NFSv4 COMPOUND tag decode): An NFSv4 COMPOUND tag length near U32_MAX overflows the length+4Critical2024
- Cisco Nexus Dashboard Fabric Controller (path traversal to RCE via SCP): A low-privileged authenticated attackerHigh2024
- Cisco Nexus Dashboard Fabric Controller (SQL injection): A read-only NDFC user executes arbitrary SQL on the controllerHigh2024
- Deep Sea Electronics DSE855 generator communications gateway: Six unauthenticated flaws in one device: two stack-basedHigh2024
- Socomec DIRIS Digiware M-70 1.6.9 (Modbus TCP and Modbus RTU-over-TCP): A large cluster of unauthenticated ModbusHigh2024
- VMware Aria Automation (SQL injection): An authenticated user injects SQL and performs unauthorized read/writeHigh2024
- Ceph RADOS Gateway (RGW): RGW accepts a JWT whose header declares alg "none" and never checks the signature, so anyoneHigh2024
- HPE Insight Remote Support (Java deserialization): Java deserialization letting an unauthenticated attacker executeHigh2024
- Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executesHigh2024
- Intel QuickAssist Technology (QAT) software and driversHigh2024
- NetApp ONTAP 9 role-based access control: A user holding several remote accounts with different roles performs actionsHigh2024
- Ceph RADOS Gateway (RGW): One malformed PUT kills the radosgw process. Sending an object copy with an emptyHigh2024
Kubeflow (centraldashboard-angular backend, email validation regex): A catastrophically backtracking regex in theHigh2024- HPE Insight Remote Support: XML external entity injection allows remote disclosure of server informationHigh2024
- Dell OpenManage Server Administrator (XSL hijacking local privilege escalation): A local low-privileged user hijacksHigh2024
- Lenovo ThinkSystem SMM / SMM2 and FPC (command injection): An authenticated user with elevated privileges executesHigh2024
- Dell CloudLink (cluster component exception handling): A highly privileged remote attacker performs unauthorizedMedium2024
- Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients): Ceph's Python code constructs imaplib.IMAP4_SSL andMedium2024
- Cisco UCS Central Software (weak backup encryption): Weak encryption on full-state and configuration backups meansMedium2024
- Dell OpenManage Enterprise (credential disclosure): A low-privileged local user obtains stored credentials from OMEMedium2024
- Dell OpenManage Enterprise (path traversal): An unauthenticated remote attacker reads files from the OME serverMedium2024
- AMD - Global History Register side channel: A side channel through the branch predictor's Global History RegisterUnscored2024
- AMD Zen 2, Zen 3 and Zen 4 platforms with DDR4 (7/10 Zen 2 and 6/10 Zen 3 devices flipped) and DDR5 (1/10 devices)Unscored2024
202382
- AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016): Insufficient RMP checking on IOMMU host bufferMediumApr 16, 2026
- Linux i915 GVT-g mediated GPU virtualisation (debugfs teardown): Companion to the vGPU debugfs cleanup bug: GVT-gHighDec 24, 2025
- Linux HID/amd_sfh - shift out of bounds: A shift operation in the AMD Sensor Fusion Hub driver exceeds the maximumUnscoredOct 22, 2025
- Linux i915 GVT-g mediated GPU virtualisation: Unsafe cleanup of per-vGPU debugfs state when a mediated vGPU isMediumOct 7, 2025
- Linux x86/MCE - CS register not saved on AMD Zen Instruction Fetch Poison errors: On AMD Zen systems, the InstructionMediumSep 18, 2025
- Linux perf/x86/amd/core - overflow status not cleared for unhandled indices: Unhandled overflow bits are left setMediumMay 2, 2025
- RKE / Rancher (k8s control plane): full-cluster-state configmap in kube-system readable by non-adminsCriticalOct 16, 2024
- AMD SMM communications buffer - TOCTOU (AMD-SB-3003): A time-of-check-to-time-of-use race on the SMM communicationsHighAug 13, 2024
- AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003): The IOMMU is not re-initialized during a Dynamic Root ofMediumAug 13, 2024
Acronis Cyber Infrastructure: Default passwordsCriticalJul 24, 2024- Linux x86/mm - pfn_to_kaddr() 64-bit input handling (SNP support code): On 64-bit platforms the pfn_to_kaddr() macroMediumMay 17, 2024
- Intel Data Center GPU Max Series 1100 / 1550: An improper conditions check lets a privileged local user takeMediumMay 16, 2024
Ceph RGW (IBM Spectrum Fusion HCI): Improper bucket access lets an actor perform unauthorized actions in RGWMediumMay 14, 2024
A10 Thunder ADC (FileMgmtExport): An authenticated attacker can walk outside the intended export directoryHighMay 3, 2024- Fortinet FortiClient EMS: Unauthenticated SQL injectionCriticalMar 12, 2024
Lustre (incorrect access control, 2.13.x-2.15.x before 2.15.4): Incorrect access control in Lustre lets an attackerCriticalMar 7, 2024- Citrix NetScaler ADC/Gateway: Buffer overflow causing denial of service when configured as Gateway or AAA vserverHighJan 17, 2024
- Citrix NetScaler ADC/Gateway: Code injection on the management interfaceMediumJan 17, 2024
- GitLab: Password reset email deliverable to an unverified addressCriticalJan 12, 2024
Ivanti Connect Secure: Web-component authentication bypass reaching restricted resourcesHighJan 12, 2024
OpenSSH through 10.0 - mm_answer_authpassword uses an integer 'authenticated' flag that does not resist a single bitHighDec 24, 2023- Keycloak: Wildcard in the JARM form_post.jwt response modeMediumDec 18, 2023
- Keycloak: Redirect scheme filtering bypassed by appending a wildcardMediumDec 14, 2023
- OpenZFS: Block-cloning path can replace file contents with zero bytes, potentially disabling security mechanismsHighNov 24, 2023
- AMD SMM Supervisor (AMD-SB-7011): The highest-scored AMD platform CVE in this database at 9.8 critical. A flaw in theCriticalNov 14, 2023
- AMD Radeon Graphics display driver - input validation: Improper input validation in the Radeon display driver letsHighNov 14, 2023
- AMD Radeon RX Vega M graphics driver installer - signature verification: The driver package launchesMediumNov 14, 2023
- OpenVINO Model Server: Input-validation flaw in OpenVINO Model Server reachable without authenticationMediumNov 14, 2023
Samba: Path traversal in client pipe namesCriticalNov 3, 2023
Samba: SMB client can truncate files despite read-only permissions when acl_xattr ignores system ACLsMediumNov 3, 2023- Linux NVMe-oF (nvmet-tcp): Use-after-free/double-free in nvmet_tcp_free_cryptoHighNov 1, 2023
- Elasticsearch: Crafted _search query stringMediumOct 26, 2023
- RabbitMQ: HTTP API enforces no request body limitMediumOct 25, 2023
- AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory access: Improper privilegeHighOct 17, 2023
- MySQL Server: InnoDB flaw - a high-privileged network attacker can hang or repeatedly crash the serverMediumOct 17, 2023
- Citrix NetScaler ADC/Gateway: "CitrixBleed" - memory overread leaking valid session tokensCriticalOct 10, 2023
- HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesetsHighSep 29, 2023
- JetBrains TeamCity: Authentication bypass leading to remote code execution on TeamCity ServerCriticalSep 19, 2023
- Argo CD: repo-server extracts a user-controlled tar.gz without size validationMediumSep 7, 2023
Digi RealPort protocol (Digi console/terminal servers): RealPort is the protocol Digi console servers use to exposeCriticalAug 31, 2023- Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2a: Remote unauthenticated users can bypass webHighAug 31, 2023
- Broadcom LSI Storage Authority (LSA) - on-disk credential/key storage on Linux and Windows: The keys LSA usesMediumAug 15, 2023
- AMD SMM - memory corruption (AMD-SB-4003): Memory corruption reachable in System Management Mode. Same class as theHighAug 8, 2023
- Keycloak: OIDC authentication flaw - attacker reusing data from a same-realm request impersonates a userMediumAug 4, 2023
- Citrix NetScaler ADC/Gateway: Unauthenticated remote code execution on the gateway applianceCriticalJul 19, 2023
- Grafana: Azure AD accounts validated on the mutable, non-unique email claimCriticalJun 22, 2023
- Fortinet FortiOS / FortiProxy SSL-VPN: A heap-based buffer overflow in the SSL-VPN daemon lets a remoteCriticalJun 13, 2023
- Apache Guacamole: Miscalculated instruction lengths during the Guacamole handshakeMediumJun 7, 2023
Progress MOVEit Transfer: Unauthenticated SQL injection into the web appCriticalJun 2, 2023
DMTF libspdm - SPDM Requester timeout handling: A libspdm Requester stores the Responder's CTExponentMediumJun 1, 2023- GitLab: Unauthenticated path traversal reads arbitrary server files when an attachment sits under 5+ nested groupsCriticalMay 26, 2023
- etcd: LeaseTimeToLive exposes key names to a user without read permission on those keysLowMay 11, 2023
DMTF libspdm - SPDM session establishment (reference implementation used in GPU/device attestation): A deviceCriticalMay 8, 2023
CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux): A default passwordCriticalApr 24, 2023
CyberPower PowerPanel Business - default.cmd file upload: Unrestricted upload of a dangerous file type into default.cmdCriticalApr 24, 2023
Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - device credential endpoints: IncorrectHighApr 18, 2023
Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - Device File Transfer settings: MissingHighApr 18, 2023
Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpoint: Code injectionHighApr 18, 2023- MinIO: Windows deployments fail to filter `\`HighMar 22, 2023
- MinIO: Crafted request bypasses PostPolicyBucket metadata bucket-name checkHighMar 22, 2023
- MinIO: Cluster returns all env vars incl. MINIO_SECRET_KEY and MINIO_ROOT_PASSWORDHighMar 22, 2023
- Veeam Backup & Replication: Encrypted credentials in the configuration database can be obtainedHighMar 10, 2023
HAProxy (before 2.7.3): HAProxy's HTTP/1 header parser accepts empty header field names, which can be used to makeCriticalFeb 14, 2023- Apache Kafka Connect: Attacker able to create/modify a connector sets a SASL JAAS JndiLoginModule configHighFeb 7, 2023
- Netdata: Agent MACHINE GUID is readable and reusableMediumJan 14, 2023
- ZKTeco-based OEM biometric access terminals (ZKTeco ProFace X, Smartec ST-FR043/ST-FR041ME and rebadged equivalents)Critical2023
- VMware Aria Automation (missing access control): An authenticated user reaches remote organizations and workflows theyCritical2023
- Pure Storage FlashBlade management interface authentication: An attacker authenticates to the FlashBlade managementCritical2023
IBM Storage Scale session management: An authenticated user steals or fixates another user's active session andHigh2023
OpenPMIx (PMIx library used by Slurm and Open MPI for job launch): A race in PMIx library code that executes with UID 0High2023
HPE OneView (command injection with local privilege escalation): A low-privileged local user on the OneView applianceHigh2023- NetApp ONTAP 9 HTTP service: An unauthenticated attacker crashes the ONTAP HTTP service, taking down the management andHigh2023
- Software House iSTAR Ultra, Ultra LT, Ultra G2 and Edge G2 door controllers: An unauthenticated user can logHigh2023
- ZKTeco BioTime v8.5.5 (iclock API path traversal): Unauthenticated arbitrary file read on the BioTime serverHigh2023
- KNX devices using KNX Connection Authorization Option 1 (BCU key): An attacker sets the BCU key on KNX devicesHigh2023
- Johnson Controls Metasys NAE55 / SNE / SNC network engines and Facility Explorer F4-SNC (before 11.0.6 / 12.0.4)High2023
Slurm (NULL pointer dereference in RPC handling): A crafted message crashes the Slurm daemon. On slurmctld that stallsHigh2023
HPE OneView (clusterService authentication bypass to DoS): Authentication bypass against the OneView cluster serviceHigh2023
Kubeflow (central dashboard, reflected cross-site scripting): Reflected XSS in the Kubeflow dashboard runs attackerMedium2023- ZKTeco BioAccess IVS v3.3.1 access control platform: An unauthenticated attacker can open and close any doorMedium2023
- Pure Storage FlashBlade object store protocol: An authenticated object-store user degrades both data access andMedium2023
- FlyteAdmin (list endpoints, SQL injection through list filters): FlyteAdmin's list endpoints interpolate filterLow2023
202273
- Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttling: A race between AMD PMU enablementMediumMay 1, 2025
- Harbor registry: P2P preheat execution logs readable/updatable by any authenticated user via job ID enumerationHighNov 14, 2024
- Linux swiotlb - info leak with DMA_FROM_DEVICE bounce buffers: The software IO TLB leaks information through bounceMediumJul 16, 2024
IBM Storage Scale Container Native Storage Access (namespace boundary): A local attacker can initiate connections fromHighFeb 17, 2024
IBM Spectrum Scale Container Native Storage Access: A local user obtains root privileges through the Spectrum ScaleHighApr 29, 2023
IBM Spectrum Scale / Storage Scale Container Native Storage Access: Programs running inside a container can overcomeHighApr 26, 2023- Intel C++ Compiler Classic / oneAPI toolkits (Unicode source handling): Improper handling of Unicode bidirectionalHighFeb 16, 2023
- Intel oneAPI DPC++/C++ compiler (homoglyph rendering): Homoglyph characters are not visually distinguishedHighFeb 16, 2023
- Intel oneAPI Data Analytics Library (oneDAL): An uncontrolled library search path: the component loads a shared libraryMediumFeb 16, 2023
- Intel MPI Library (oneAPI HPC Toolkit): An uncontrolled library search path: the component loads a shared libraryMediumFeb 16, 2023
- Intel oneAPI Deep Neural Network Library (oneDNN): An uncontrolled library search path: the component loads a sharedMediumFeb 16, 2023
- Intel oneAPI OpenMP runtime: An uncontrolled library search path: the component loads a shared library by nameMediumFeb 16, 2023
- Intel oneAPI DPC++/C++ compiler runtime: An uncontrolled library search path: the component loads a shared libraryMediumFeb 16, 2023
- Intel oneAPI Collective Communications Library (oneCCL): An uncontrolled library search path: the component loadsMediumFeb 16, 2023
Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storage: DCE stores device passwordsHighJan 30, 2023
Schneider Electric Data Center Expert (versions prior to v7.9.0) - Java deserialization: Unsafe deserialization of dataHighJan 30, 2023
Imagination PowerVR GPU driver - cache subsystem information page: The driver's cache-subsystem information pageMediumJan 26, 2023- Ceph: ceph-crash.service local privilege escalation to root plus privileged crash-dump disclosureHighJan 17, 2023
- Fortinet FortiOS: SSL-VPN heap-based buffer overflowCriticalJan 2, 2023
- Citrix ADC/Gateway: SAML SP/IdP configCriticalDec 13, 2022
- Brocade Fabric OS (unauthenticated remote code execution): Unauthenticated remote code execution on a Fibre ChannelCriticalDec 8, 2022
- Prometheus (exporter-toolkit): Poisoning the built-in auth cache bypasses basic-auth on exportersMediumNov 29, 2022
Tailscale (Windows client): Local API bound to a TCP socketCriticalNov 23, 2022- Linux nfsd (NFS server): NFSD buffer overflow - a client can force the send buffer to overflow the page arrayHighNov 4, 2022
- Brocade Fabric OS CLI: A remote authenticated attacker can act beyond their role through the Fabric OS CLIHighOct 25, 2022
- Fortinet FortiOS/FortiProxy: Auth bypass via an alternate pathCriticalOct 18, 2022
- Grafana: A user can block another user's login by registering their email address as a usernameMediumOct 13, 2022
- HashiCorp Consul: Internal RPC endpoint does not check multiple SAN URIs in a CSRMediumSep 23, 2022
- PostgreSQL: Autovacuum, REINDEX, CLUSTER etc. apply protections too lateHighAug 31, 2022
Samba (AD DC): KDC and kpasswd share keysHighAug 25, 2022
Samba (AD DC): KDC accepts kpasswd requests encrypted with any key it knowsHighAug 25, 2022- Intel Data Center Manager: Improper access control in Data Center Manager lets an unauthenticated attackerHighAug 18, 2022
- Intel Data Center Manager: Improper neutralisation (injection) in Data Center Manager lets an authenticated userHighAug 18, 2022
Ampere Altra before 1.08g and Altra Max before 2.05a - return address prediction: An attacker can controlHighAug 17, 2022- Ceph Manager (volumes plugin): Owner of one CephFS share can read/write any share or the entire file systemCriticalJul 25, 2022
- Cisco Nexus Dashboard (web UI / CSRF): One of a batch of unauthenticated flaws in Nexus Dashboard that together allowCriticalJul 21, 2022
- Grafana: Stored XSS via Unified AlertingHighJul 15, 2022
- Brocade SANnav Management Portal - Zone management endpoints, before SANnav 2.2.0: SQL injection in multiple endpointsCriticalMay 6, 2022
- F5 BIG-IP (iControl REST): An unauthenticated attacker can send undisclosed requests to the iControl REST managementCriticalMay 5, 2022
- Redis: Lua environment weakness lets a user inject code that runs with another Redis user's privilegesLowApr 27, 2022
- Redis: Crafted Lua script triggers a NULL pointer dereferenceLowApr 27, 2022
- MySQL Server: InnoDB flaw allowing a high-privileged network attacker to cause a repeatable DoSMediumApr 19, 2022
- MinIO: Non-admin user can create service accounts for root/admin users and assume their policiesHighApr 12, 2022
- Redis: Debian/Ubuntu packaging leaves a Lua sandbox escapeCriticalFeb 18, 2022
Zabbix: Unverified user login in session data (SAML SSO enabled)CriticalJan 13, 2022
Zabbix: Some setup.php steps reachable by unauthenticated usersLowJan 13, 2022
Windows Boot Manager: Secure Boot bypass exploited in the wild by the BlackLotus UEFI bootkitMediumJan 11, 2022- Software House iSTAR Ultra door controller (before 6.8.9.CU01): Unauthenticated command injection giving rootCritical2022
- HID Mercury intelligent controllers sold by Carrier LenelS2 (LNL-X2210/X2220/X3300/X4420/4420Critical2022
- Pure Storage Purity//FA and Purity//FB management interface (exposed credential): A password for the array's managementCritical2022
- Linux NFS server (nfsd, nfssvc_decode_writeargs): The NFSv2/v3 write argument decoder has no lower bound on the lengthCritical2022
- FlyteConsole (cors_proxy endpoint): FlyteConsole's cors_proxy forwards attacker-chosen URLs, so anyone who reaches theCritical2022
- HTCondor (CLAIMTOBE authentication method): Once a user has authenticated to a daemon with CLAIMTOBE - a method thatHigh2022
- Honeywell Alerton Visual Logic, Ascent Control Module (ACM) and Compass 1.6.5: Unauthenticated program writesHigh2022
- Pure Storage Purity//FA and Purity//FB restricted shell (Python environment variables): A logged-in user manipulatesHigh2022
- Pure Storage Purity//FA and Purity//FB restricted shell (environment variables): A second route out of the restrictedHigh2022
- NetApp ONTAP SnapLock on FlexGroup volumes: An authenticated remote user modifies or deletes WORM-locked data beforeHigh2022
- Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191: Use-after-freeHigh2022
IBM Storage Scale Container Native Storage Access (pod security context): A local user in a CNSA-served containerHigh2022
IBM Spectrum Scale container image (command execution): A local attacker runs arbitrary commands inside the SpectrumHigh2022- Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi): Unauthenticated arbitrary file read off the gatewayHigh2022
- FlyteAdmin (built-in OAuth authorization server, default client secret hashes): Turning on Flyte's built-inHigh2022
IBM Storage Scale Container Native Storage Access (network namespace exposure): Hosts outside the cluster can openHigh2022
Schneider Electric APC NetBotz 4 environmental appliances (355/450/455/550/570, V4.7.0 and prior): No rate limitingHigh2022- GlusterFS (dht translator, dht_setxattr_mds_cbk): A use-after-free in the distributed-hash translator crashes the brickHigh2022
- MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intendedHigh2022
IBM Spectrum Scale Container Native Storage Access (CSI volume handling): Anyone who can create a pod plus a PV/PVCMedium2022
IBM Spectrum Scale Data Access Services (DAS): An authenticated DAS user inserts code that manipulates clusterMedium2022- FlyteAdmin (external IdP access token / ID token expiration check): FlyteAdmin does not enforce expiry on access and IDMedium2022
Slurm (openSUSE slurm-testsuite packaging): The openSUSE slurm testsuite package ships files with permissive defaultMedium2022
Rittal CMC III cabinet lock / access-card system: The access cards used to open control cabinets secured with RittalMedium2022
BeeGFS (client-to-metadata/storage service authentication, connAuthFile): Class entry, not a single CVE. Before BeeGFSUnscored2022
BeeGFS (client-to-metadata/storage service authentication, connAuthFile): Class entry, not a single CVE. Before BeeGFSUnscored2022
202169
- AMD PSP1 Configuration Block (APCB) parsing: An out-of-bounds memory write while the platform processes the AMD PSP1HighAug 13, 2024
- AGESA Boot Loader (ABL) - SPI ROM header input validation (AMD-SB-3003): The AGESA Boot Loader does not properlyLowAug 13, 2024
- AMD TEE / ASP bootloader syscall input validation: Insufficient validation of syscall inputs in the AMD trustedMediumMay 9, 2023
- etcd: Authentication flaw via the debug functionCriticalApr 4, 2023
- Ceph: Key length incorrectly passed to the encryption algorithmMediumAug 25, 2022
Imagination PowerVR GPU driver - pinned memory lifecycle: An unprivileged app allocates pinned GPU memory, unpins it soCriticalAug 24, 2022
Imagination PowerVR GPU driver - memory residue: An unprivileged application gets the GPU driver to hand backUnscoredAug 24, 2022
Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05HighAug 17, 2022- AMD Zen 1 / Zen 2 / Zen 3 - execution unit scheduler queue contention (SMT): AMD's split scheduler design gives eachMediumAug 10, 2022
- AMD AGESA Boot Loader (ABL) / ASP stage-2 bootloader: A malicious or compromised User Application or AGESA Boot LoaderMediumMay 12, 2022
- AMD CPU core logic - core hang triggered from an unprivileged VM: Specific code executed from an unprivileged VM canMediumMay 11, 2022
Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: Path traversal to remote code executionCriticalApr 13, 2022
Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: OS command injection over the networkCriticalApr 13, 2022
Moxa NPort IAW5000A-I/O serial device server: The built-in web server doesn't validate input properly, letting a remoteCriticalApr 1, 2022- ClickHouse: Attacker-controlled offset in the LZ4 codecHighMar 14, 2022
- ClickHouse: Second heap out-of-bounds read in LZ4::decompressImpl reachable from a client queryHighMar 14, 2022
- PostgreSQL: With cert/trust+clientcert auth, a MITM can inject arbitrary SQL at connection setupHighMar 4, 2022
- Brocade Fabric OS (hard-coded credentials): Documented hard-coded credentials in Brocade Fabric OSCriticalFeb 21, 2022
Samba (SMB gateway): Out-of-bounds heap read/write in vfs_fruitHighFeb 21, 2022- AMD System Management Mode (SMM) interrupt handler: A flaw in the AMD SMM interrupt handler lets a high-privilegeHighFeb 16, 2022
- Intel SPS (HECI subsystem compartmentalisation): Insufficient compartmentalisation in the HECI interfaceMediumFeb 9, 2022
- MinIO: Hand-crafted admin API call updates a user's policyHighDec 27, 2021
Microsoft iSNS Server service (Internet Storage Name Service for iSCSI discovery): Memory corruption in the iSNS ServerCriticalDec 15, 2021- Grafana: Unauthenticated directory traversal via /public/plugins/<id>/HighDec 7, 2021
- PC-DDR4 / LPDDR4X DRAM - Target Row Refresh mitigation: Non-uniform Rowhammer patterns triggered bit flips on every oneCriticalNov 16, 2021
- AMD System Management Unit (SMU) mailbox interface: A malicious user can manipulate SMU mailbox entries and reachHighNov 16, 2021
- Broadcom Emulex HBA Manager / OneCommand Manager (Fibre Channel and FC-NVMe HBAs), before 11.4.425.0 and 12.8.542.31CriticalNov 12, 2021
HPE ProLiant Gen10 System ROM (security restriction bypass): A local bypass of security restrictions in the System ROMMediumNov 1, 2021- Grafana: Unauthenticated access to snapshots via /api/snapshots/:keyCriticalOct 5, 2021
- Cisco APIC / Cloud APIC (API endpoint): Unauthenticated arbitrary file read and write on the APICCriticalAug 25, 2021
- Dell OpenManage Enterprise (remote code execution): Remote code execution on the OpenManage Enterprise consoleCriticalAug 9, 2021
- Terraform Enterprise: Missing authorization on a subset of run-token API requestsHighJul 20, 2021
- linuxptp / ptp4l (PTP message forwarding): A missing length check when ptp4l forwards a PTP message between ports leaksHighJul 9, 2021
- linuxptp / ptp4l (transparent clock on little-endian): A crafted PTP packet against ptp4l running as a transparentHighJul 9, 2021
- RabbitMQ: Unsanitized username rendered in the management UILowJun 28, 2021
- GitLab: unauthenticated SSRF through webhooks reaches the internal networkCriticalJun 11, 2021
- Ceph RGW: HTTP header injection via a newline in the CORS ExposeHeader tagMediumMay 17, 2021
- GitLab: Image files passed unvalidated to a file parser (ExifTool)CriticalApr 23, 2021
- Eaton Intelligent Power Manager (IPM) prior to 1.69: Unauthenticated remote code execution on Eaton's power-managementCriticalApr 13, 2021
- Eaton Intelligent Power Manager (IPM) prior to 1.69 - dynamic eval: Unauthenticated eval injection: user-controlledHighApr 13, 2021
- Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.js: Unauthenticated arbitrary file deletionHighApr 13, 2021
SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01): A zero-length PDU sent where data is expectedHighMar 13, 2021- Linux iSCSI: iSCSI netlink structures lack length checksHighMar 7, 2021
- Linux iSCSI: Unprivileged user can craft Netlink messages to scsi_transport_iscsiHighMar 7, 2021
- Linux iSCSI: Kernel pointer leak - iscsi_transport handle exposed to unprivileged users via sysfsMediumMar 7, 2021
- Cisco ACI Multi-Site Orchestrator (Application Services Engine): Complete unauthenticated authentication bypass on theCriticalFeb 24, 2021
- Cisco Nexus 3000/9000 (internal file management service): Unauthenticated remote file write, read and delete as rootCriticalFeb 24, 2021
- Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN): A device plugged into a normal front-panel port can talk itsHighFeb 24, 2021
Nagios XI: OS command injection in the windowswmi config wizard (authenticated)HighFeb 15, 2021
Nagios XI: OS command injection in the switch config wizardHighFeb 15, 2021
Nagios XI: OS command injection in the cloud-vm config wizardHighFeb 15, 2021- tcmu-runner 1.3.x - 1.5.2 (userspace backstore handler for the Linux LIO target, used by Ceph iSCSI gateways and otherHighJan 13, 2021
- HTCondor (condor_credd): condor_credd can be told to create or write files as root outsideCritical2021
- Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllers: A cluster of critical flawsCritical2021
- HTCondor (IDTOKENS authentication): A flaw in IDTOKENS lets a user authenticate as another user or as the condorHigh2021
- MinIO (IAM policy engine): A regular user can step outside the policy restrictions applied to them, reaching operationsHigh2021
- HTCondor (SciTokens authentication): A SciToken is granted more authorization than the token's scopes should permit.High2021
- HTCondor (condor_schedd, condor_collector): A user with nothing more than READ access to the schedd or collector canHigh2021
- HTCondor (S3 file transfer, daemon logs and job ClassAds): Pre-signed S3 URLs for a job's input and output are writtenHigh2021
IBM Spectrum Scale core component (format string handling): A user with a shell on any node that runs Storage ScaleHigh2021- NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removingHigh2021
- HTCondor (daemon-to-daemon channel, negotiator/startd/schedd): Secret material crosses the network in the clear whenHigh2021
- Ceph MON (CephX authentication): The monitor does not sanitize other_keys when handling CEPHX_GET_AUTH_SESSION_KEY, soHigh2021
Slurm (slurmdbd, AccountingStoreFlags=job_script / job_env): When the site turns on job-script and job-environmentMedium2021- Intel 82599 Ethernet Controllers and Adapters - network-on-chip shared-resource isolation: Improper isolation of sharedMedium2021
IBM Spectrum Scale file audit logging retention: A privileged administrator deletes audit records before theirMedium2021- NATS server (TLS ciphersuite selection via CLI flags): A configuration footgun in the cluster message bus: NATSLow2021
IBM Spectrum Scale file audit logging: A local user touches files without the access being recorded, so the audit trailLow2021- DDR4 DRAM with in-DRAM TRR; a coupling effect that reaches rows at distance two rather than immediate neighboursUnscored2021
202033
IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1: Unauthorized access to user data, or injection ofCriticalMay 24, 2022- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (improper input validation) reachableMediumFeb 17, 2021
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (insufficient access control leadingMediumFeb 17, 2021
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (uncontrolled resource consumption)MediumFeb 17, 2021
- Replay Protected Memory Block (RPMB) protocol as specified for eMMC, UFS and ALL versions of NVMeMediumNov 18, 2020
- Intel Data Center Manager Console: Improper input validation in the DCM Console lets an authenticated user escalateHighNov 12, 2020
- Brocade Fabric OS REST API: Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remoteCriticalSep 25, 2020
APC PowerChute Business Edition (v9.0.x and earlier): PowerChute runs the shutdown script that fires when a UPS reportsHighAug 31, 2020
Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management): The earlier cluster on the same consoleCriticalAug 25, 2020
Marvell QConvergeConsole (QLogic adapter management): Remote code execution on QConvergeConsole, the managementHighAug 25, 2020- Fortinet FortiOS SSL-VPN: A logic flaw lets a user who changes their login case (e.gCriticalJul 24, 2020
- ntpd (transmit timestamp prediction): A remote attacker who can predict transmit timestamps can crash ntpd or, worseHighJun 4, 2020
- AMD ATI atillk64.sys - physical memory mapping driver: The AMD ATI atillk64.sys driver exposes routines that mapHighApr 27, 2020
- ntpd (NTP.org reference implementation): An off-path attacker can block a node's unauthenticated time synchronizationHighApr 17, 2020
- targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)HighApr 15, 2020
- DDR4 / LPDDR4 DRAM - Target Row Refresh mitigation: Many-sided Rowhammer defeats the in-DRAM Target Row RefreshUnscoredMar 10, 2020
Slurm (Gentoo ebuild pkg_postinst): The Gentoo packaging runs chown across paths on the live root filesystem duringCritical2020- Ceph CephX authentication protocol: CephX does not correctly bind client identity, so an attacker who can captureHigh2020
Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1: Authenticated file uploadHigh2020
IBM Spectrum Scale / Storage Scale core daemon (cluster RPC transport): An attacker who can speak to the cluster'sHigh2020- Ceph MON / MGR (ceph-mon, ceph-mgr): Ceph-mon and ceph-mgr fail to enforce the caps on an authenticated principal, so aHigh2020
IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions): With specific debug settings enabled, LSFHigh2020
IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials): A user who is merely allowed to submit LSF jobsHigh2020- Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills theHigh2020
- Ceph dashboard (ceph-mgr dashboard module): An unauthenticated HTTP request with traversal sequences reads arbitraryHigh2020
IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can sendHigh2020- CephFS (via OpenStack Manila native driver): A Manila user can request access for an existing CephFS identity and getHigh2020
- RPMB protocol message authentication subsystem in Intel TXE before 4.0.30 (replay-protected memory block)Medium2020
IBM Spectrum Scale mmfsd daemon (RPC request handling): A local attacker floods mmfsd with RPC requests and crashes itMedium2020
Slurm (X11 forwarding, xauth magic-cookie setup): Slurm shells out to xauth to install a user's X11 magic cookie, andLow2020- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM determines whether data exists on aLow2020
- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM enumerates the names of other SVMs andLow2020
- AMD Zen 1 / Zen+ / Zen 2 - L1D cache way predictor: AMD's L1D way predictor hashes virtual addresses to predict whichUnscored2020
201937
Vertiv Avocent UMG-4000 universal management gateway: Every command the UMG-4000's web interface runs executes as rootHighMar 30, 2020
Vertiv Avocent UMG-4000 universal management gateway: An authenticated admin can plant a maliciously named fileMediumMar 30, 2020
Lustre ptlrpc module (server-side client packet validation): A Lustre client can send a crafted RPC that overflows aCriticalJan 27, 2020
Lustre ptlrpc / mdt modules (client-driven server panic family): The head of a family of ten Lustre defectsHighJan 27, 2020
Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions throughHighDec 19, 2019
BeeGFS (beegfs-ctl / metadata server): Authentication bypass by talking directly to a BeeGFS metadata server. BeeGFS isCriticalDec 5, 2019- Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270: Same class of in-flight data leakMediumNov 14, 2019
- Cisco Nexus 9000 ACI Mode (LLDP subsystem): A buffer overflow in the LLDP subsystem of Nexus 9000 switches in ACI modeHighJul 31, 2019
CyberPower PowerPanel Business Edition 3.4.0 Agent/Center: Cross-site request forgery across all forms in the webHighJul 10, 2019- DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issue: TurnsLowJun 13, 2019
Slurm (slurmdbd, sacctmgr archive load): A second SQL injection path into SlurmDBD, this one through the 'sacctmgrCritical2019- HTCondor (condor_startd, condor_schedd, condor_shadow): One CVE covering four separate authentication failures theCritical2019
- NetApp ONTAP Select Deploy administration utility (HTTP service): An unauthenticated attacker performs administrativeCritical2019
- NetApp ONTAP Select Deploy administration utility (credential transport): Deploy sends its credentials in plaintext, soCritical2019
- NetApp ONTAP Select Deploy administration utility (code injection): An unauthenticated remote attacker injects code andCritical2019
Slurm (32-bit RPC handling): Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control ofCritical2019- Optergy Proton / Enterprise building management platform: A backdoor console giving remote root code executionCritical2019
- Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra service: Unauthenticated remote code executionCritical2019
IBM Spectrum Scale management GUI: Any authenticated GUI user - including a low-privilege monitoring account - runsHigh2019- Altair PBS Professional / OpenPBS (pbs_mom): Pbs_mom, the daemon that executes jobs on every compute node, acceptsHigh2019
- MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controlsHigh2019
IBM Spectrum Scale administrative command path: A local unprivileged user becomes root on a Storage Scale node byHigh2019- Ceph RADOS Gateway (RGW, Beast frontend): An unauthenticated client can crash radosgw by sending valid headers followedHigh2019
Slurm (srun --uid): Srun --uid drops privileges in the wrong order, so a step launched through it can end up runningHigh2019
Lustre (mdt module, mdt_object_remote): A client sends a packet with unvalidated fields and the metadata serverHigh2019
Lustre (ptlrpc module): Out-of-bounds write in the RPC layer, reachable by a client that lies about packet field sizes.High2019
Lustre (ptlrpc module): A second out-of-bounds access in ptlrpc triggered by unvalidated client packet fields, endingHigh2019
Lustre (ptlrpc module): Out-of-bounds read in ptlrpc leading to a server panic. The read primitive also means serverHigh2019
Lustre (ptlrpc module, lm_bufcount handling): A client that modifies the lm_bufcount field walks the server off the endHigh2019
Lustre (mdt module, MDT Body eadatasize): An oversized eadatasize field in an MDT request drives the metadata serverHigh2019
Lustre (ptlrpc, osd_map_remote_to_local): Out-of-bounds access in the object-storage mapping path, reachable from aHigh2019
Lustre (mdt module): Another unvalidated-field out-of-bounds access in the metadata server, ending in a panic. SameHigh2019- NetApp Clustered Data ONTAP (unauthenticated information disclosure): An attacker with no account extracts sensitiveHigh2019
- NetApp ONTAP Select Deploy administration utility (privilege escalation): An administrative user of the Deploy utilityHigh2019
Slurm (slurmdbd.conf file permissions): slurmdbd.conf is installed world-readable, which leaks the accountingMedium2019- PCIe Address Translation Services on hosts using an IOMMU/SMMU for device isolationUnscored2019
- PCIe Address Translation Services on hosts using an IOMMU/SMMU for device isolationUnscored2019
20152
201838
Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0: CC-SG is Raritan's single-pane-of-glass gateway thatCriticalNov 18, 2019- Intel Core and Xeon CPUs - INTEL-SA-00210: This one is availability, not confidentiality, and it is the mostMediumNov 14, 2019
- Nouveau display driver (in-tree Linux nouveau, NV117): Remote denial of service against a workstation or node runningMediumApr 1, 2019
- Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitiveCriticalDec 3, 2018
Schneider Electric Data Center Expert 7.5.0 and earlier - zip upload: A crafted zip uploaded through the DCE UI canHighNov 30, 2018- Cisco IOS XE MACsec Key Agreement (MKA over EAP-TLS): A logic error in MKA over EAP-TLS lets an unauthenticatedHighOct 5, 2018
HPE iLO3/4/5: Arbitrary code execution on the iLOHighSep 27, 2018- Intel Data Center Manager SDK (reference UI): The DCM SDK's reference UI allows an unauthenticated remote attackerCriticalSep 12, 2018
HPE iLO3/4/5: Remote unauthenticated denial of service against the management controllerHighAug 14, 2018
HPE iLO4 / iLO5: Remote code execution on the management controllerHighAug 6, 2018- ntpq / ntpdc (NTP 4.2.8p11 client utilities): Stack buffer overflow in the ntpq and ntpdc command-line tools via a longCriticalJun 20, 2018
Kemp LoadMaster (LMOS): A flaw in session management lets a remote, unauthenticated attacker bypass the LoadMaster'sCriticalMay 25, 2018- AMD EPYC / Ryzen - Hardware Validated Boot enforcement: Hardware Validated Boot is not properly enforced, so anCriticalMar 22, 2018
- AMD EPYC Server - protected memory region access control: Insufficient access control over protected memory regions onCriticalMar 22, 2018
- ntpd (protocol engine, zero-origin timestamp): Continually sending packets with a zero-origin timestamp lets a remoteHighMar 6, 2018
- Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api): rbd-target-api ships with the Werkzeug debug console enabledCritical2018
Slurm (slurmdbd accounting database daemon): SQL injection into SlurmDBD gives an attacker read and write control ofCritical2018- GlusterFS (brick, server-rpc-fops.c): Multiple stack buffer overflows from fixed-size alloca() allocations in the brickHigh2018
- GlusterFS (brick, gfs3_symlink_req): Symlink creation is not confined to the volume, so a client plants a link pointingHigh2018
- NetApp Clustered Data ONTAP export policy enforcement (SMBv2/SMBv3): Export policy rules marked read-only are notHigh2018
- Ceph MON (ceph-mon): The monitor accepts pool create/delete and snapshot operations from any authenticated user thatHigh2018
- GlusterFS (brick, gfs3_mknod_req): A crafted mknod RPC traverses out of the volume and writes a file anywhere the brickHigh2018
- GlusterFS (glusterd, auth.allow): The auth.allow option does not actually restrict who may connect, so anyHigh2018
IBM Spectrum Scale daemon (GSKit cryptographic library dependency): A local attacker takes control of the SpectrumHigh2018- GlusterFS (brick, mknod): Mknod can create device nodes that point at real devices on the storage server, so a clientHigh2018
- Ceph CephX authentication protocol: An attacker who sniffs the storage network can replay a CephX authenticationHigh2018
- Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm): The IntelliSlot cardHigh2018
- SPI flash descriptor region configuration on a wide range of Supermicro boards: Any software running with sufficientMedium2018
- GlusterFS (glusterd management): An authenticated TLS client can use gluster cli --remote-host to add itself to theMedium2018
- GlusterFS (dict_unserialize): A negative key length in a serialized dict makes the server read memory from elsewhere inMedium2018
- Ceph CephX authentication protocol: The CephX signature calculation can be bypassed, so an on-path attacker can alterMedium2018
IBM Spectrum Scale / GPFS node file access path: An unprivileged but authenticated user on a GPFS node reads arbitraryMedium2018
IBM GPFS command line utility: Any unprivileged user with a shell on a GPFS node can force GPFS down on that nodeMedium2018
Slurm (user_name / gid field handling): Slurm trusts the user_name and gid fields carried in job RPCs instead ofMedium2018
IBM Spectrum LSF (job submission, file permissions): Weak file permissions in the LSF install let a local user changeMedium2018
IBM Spectrum Scale Local Read Only Cache (LROC): With LROC enabled, a read of one file can silently return the contentsLow2018- ECC DDR3 server memory on Intel Xeon (Haswell, Sandy Bridge) and AMD Opteron platformsUnscored2018
- ECC DDR3 server memory on Intel Xeon (Haswell, Sandy Bridge) and AMD Opteron platformsUnscored2018
20179
HPE iLO4: Authentication bypass and remote code execution — the "29 A's" `Connection` header bugCriticalFeb 15, 2018
HPE iLO2: Authentication bypass and code execution in iLO2 firmware 2.29CriticalFeb 15, 2018
Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who canCriticalDec 22, 2017- Intel Active Management Technology / Standard Manageability: An authentication bypass in the AMT web interface: sendingCriticalMay 2, 2017
Schneider Electric StruxureWare Data Center Expert before 7.4.0: Passwords held in cleartext in RAM on the DCIMMediumApr 30, 2017- Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) framework: Log into the Niagara platform with a disabled account nameCritical2017
- Lenovo / IBM Integrated Management Module 2 (IMM2) web administration service: The overflow is inside theCritical2017
- HTCondor (condor_schedd, GSI/VOMS extension parsing): An authenticated user crashes the schedd by feeding it malformedMedium2017
- SPI flash configuration (flash descriptor / protected range registers) across multiple Intel platformsMedium2017