Loading HuntDB...

linuxfoundation

9 Products 22 CVEs

CVE Severity Distribution (All Time)

Critical
1
High
9
Medium
4
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-37018 UNKNOWN None

The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discove…

CVE-2024-9802 MEDIUM 1 year, 1 month ago

The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific info…

CVE-2024-9798 MEDIUM 1 year, 1 month ago

The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.

CVE-2024-20089 HIGH 1 year, 2 months ago

In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execut…

CVE-2024-41265 HIGH 1 year, 3 months ago

A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest functi…

CVE-2024-6834 CRITICAL 1 year, 4 months ago

A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. Thi…

CVE-2024-5187 HIGH 1 year, 5 months ago

A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due t…

CVE-2024-37152 MEDIUM 1 year, 5 months ago

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings expo…

CVE-2024-21662 HIGH 1 year, 8 months ago

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively by…

CVE-2023-51699 MEDIUM 1 year, 8 months ago

Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection v…