Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-33194Highgolang.org/x/net: golang.org/x/net/html Infinite Loop vulnerabilityCVE-2020-25864Mediumgithub.com/hashicorp/consul: HashiCorp Consul Cross-site Scripting vulnerabilityCVE-2020-7924Mediumgithub.com/mongodb/mongo-tools: MongoDB Tools Improper Certificate Validation vulnerabilityCVE-2021-25313Mediumgithub.com/rancher/rancher: Rancher Cross-site Scripting VulnerabilityCVE-2020-8567Lowgithub.com/hashicorp/vault-csi-provider: Kubernetes Secrets Store CSI Driver plugins arbitrary file writeCVE-2020-29245Mediumgithub.com/dhowden/tag: dhowden tag panic due to out-of-bounds readCVE-2020-29244Mediumgithub.com/dhowden/tag: dhowden tag panic due to out-of-bounds readCVE-2020-29243Mediumgithub.com/dhowden/tag: dhowden tag panic due to out-of-bounds readCVE-2022-29162Mediumgithub.com/opencontainers/runc: Default inheritable capabilities for linux container should be emptyCVE-2020-10763Mediumgithub.com/heketi/heketi: Heketi logs sensitive informationCVE-2020-24303Mediumgithub.com/grafana/grafana: Grafana XSS via a query alias for the ElasticSearch datasourceCVE-2020-24710Mediumgithub.com/gophish/gophish: Gophish vulnerable to Server-Side Request ForgeryCVE-2020-8553Mediumk8s.io/ingress-nginx: ingress-nginx component for Kubernetes allows file overwriteCVE-2020-11110Mediumgithub.com/grafana/grafana: Grafana stored XSSCVE-2020-15391Criticalgithub.com/loft-sh/devspace: DevSpace vulnerable to remote code executionCVE-2020-14457Mediumgithub.com/mattermost/mattermost-server/v5: Mattermost Server Sensitive Data ExposureCVE-2018-21258Highgithub.com/mattermost/mattermost-server: Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` commandCVE-2017-18917Highgithub.com/mattermost/mattermost-server: Mattermost Server uses weak hashing for OAuth, email verification tokens and invitationsCVE-2017-18915Criticalgithub.com/mattermost/mattermost-server: Mattermost Server server restarts may provide attackers with API accessCVE-2017-18918Mediumgithub.com/mattermost/mattermost-server: Mattermost Server does not restrict SAML certificate path for System AdministratorsCVE-2017-18916Mediumgithub.com/mattermost/mattermost-server: Mattermost Server has Improper Authorization for Integration RequestsCVE-2017-18911Criticalgithub.com/mattermost/mattermost-server: Mattermost Server has X.509 Improper Certificate ValidationCVE-2017-18912Highgithub.com/mattermost/mattermost-server: Mattermost Server allows an attacker to specify a full pathname of a log fileCVE-2017-18909Highgithub.com/mattermost/mattermost-server: Mattermost Server SAML implementation does not require encryption or signature verification as defaultCVE-2017-18902Mediumgithub.com/mattermost/mattermost-server: Mattermost Server exposes team invite IDs through API endpoints

Stop the waste.
Protect your environment with Kodem.