Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
396840
AlmaLinux
3939
Alpaquita
6022
Alpine
3796
Android
3012
BellSoft Hardened Containers
216
Bitnami
5958
Chainguard
30921
CRAN
11
crates.io
1785
Debian
47810
Echo
1720
GHC
3
GIT
49508
GitHub Actions
35
Go
4609
Hackage
24
Hex
38
Linux
13573
Mageia
5668
Maven
5847
MinimOS
3390
npm
68167
NuGet
1459
openEuler
5028
openSUSE
10164
OSS-Fuzz
3675
Packagist
4806
Pub
10
PyPI
16532
Red Hat
16958
Rocky Linux
1965
RubyGems
1783
SUSE
16699
SwiftURL
36
Ubuntu
45858
Wolfi
15815
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g9vw-6pvx-7gmw
Go/github.com/envoyproxy/envoy
Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults
2 hours ago
Fix available
Severity - 7.5 (High)
GHSA-jxmr-2h4q-rhxp
Go/github.com/SpectoLabs/hoverfly
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled
4 days ago
Fix available
Severity - 7.8 (High)
GHSA-r4h8-hfp2-ggmf
Go/github.com/SpectoLabs/hoverfly
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
4 days ago
No fix available
Severity - 9.8 (Critical)
GHSA-rf24-wg77-gq7w
Go/github.com/knadh/listmonk
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
5 days ago
No fix available
Severity - 8.6 (High)
GHSA-93mf-426m-g6x9
Go/github.com/coredns/coredns
CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
5 days ago
Fix available
Severity - 7.1 (High)
GHSA-p46v-f2x8-qp98
Go/github.com/prest/prest/v2
pREST has a Systemic SQL Injection Vulnerability
6 days ago
No fix available
Severity - 9.3 (Critical)
GO-2025-3916
Go/github.com/suyuan32/simple-admin-core
simple-admin-core SQL Injection vulnerability in github.com/suyuan32/simple-admin-core
08 Sep
Fix available
GO-2025-3917
Go/github.com/neuvector/neuvector
NeuVector has an insecure password storage vulnerable to rainbow attack in github.com/neuvector/neuvector
08 Sep
No fix available
GO-2025-3918
Go/github.com/neuvector/neuvector
NeuVector admin account has insecure default password in github.com/neuvector/neuvector
08 Sep
No fix available
GO-2025-3919
Go/github.com/neuvector/neuvector
NeuVector process with sensitive arguments lead to leakage in github.com/neuvector/neuvector
08 Sep
No fix available
GO-2025-3920
Go/github.com/edgelesssys/contrast
Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast
08 Sep
Fix available
GO-2025-3921
Go/github.com/coder/coder
Go/github.com/coder/coder/v2
Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
08 Sep
Fix available
GO-2025-3923
Go/github.com/rancher/rancher
Rancher affected by unauthenticated Denial of Service in github.com/rancher/rancher
08 Sep
Fix available
GO-2025-3924
Go/github.com/hashicorp/vault
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault
08 Sep
Fix available
GO-2025-3925
Go/github.com/versity/versitygw
Versity panic induced by AWS chunked data sent to port in github.com/versity/versitygw
08 Sep
Fix available
GO-2025-3927
Go/github.com/rancher/fleet
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet
08 Sep
Fix available
Load more...
Go - OSV