Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-7594Highgithub.com/hashicorp/vault: Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By DefaultCVE-2024-22030Highgithub.com/rancher/rancher: Rancher agents can be hijacked by taking over the Rancher Server URLCVE-2024-45042Mediumgithub.com/ory/kratos: Ory Kratos's setting required_aal `highest_available` does not properly respect code + mfa credentialsCVE-2024-47003Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` eventsCVE-2024-8996Mediumgithub.com/grafana/agent: Grafana Agent (Flow mode) on Windows has Unquoted Search Path or Element vulnerabilityCVE-2024-8975Mediumgithub.com/grafana/alloy: Grafana Alloy on Windows has Unquoted Search Path or Element vulnerabilityCVE-2024-40761Mediumgithub.com/apache/incubator-answer: Apache Answer: Avatar URL leaked user email addressesCVE-2024-46957Criticalmellium.im/xmpp: Mellium allows Authentication Bypass by SpoofingCVE-2024-47062Criticalgithub.com/navidrome/navidrome: Navidrome has Multiple SQL Injections and ORM LeakCVE-2024-47060Highgithub.com/zitadel/zitadel/v2: ZITADEL Allows Unauthorized Access After Organization or Project DeactivationCVE-2024-47000Highgithub.com/zitadel/zitadel/v2: ZITADEL's Service Users Deactivation not Working CVE-2024-46999Highgithub.com/zitadel/zitadel/v2: ZITADEL's User Grant Deactivation not WorkingCVE-2024-45410Criticalgithub.com/traefik/traefik/v3: HTTP client can manipulate custom HTTP headers that are added by TraefikCVE-2023-27584Criticald7y.io/dragonfly/v2: Dragonfly2 has hard coded cyptographic keyCVE-2024-8986Criticalgithub.com/grafana/grafana-plugin-sdk-go: Grafana plugin SDK Information LeakageCVE-2023-30464Mediumgithub.com/coredns/coredns: CoreDNS Cache Poisoning via a birthday attackCVE-2023-47105Criticalgithub.com/chaosblade-io/chaosblade: Chaosblade vulnerable to OS command executionCVE-2024-46989Mediumgithub.com/authzed/spicedb: SpiceDB having multiple caveats on resources of the same type may improperly result in no permissionCVE-2023-28452Highgithub.com/coredns/coredns: CoreDNS vulnerable to TuDoor AttacksCVE-2024-7387Mediumgithub.com/openshift/builder: OpenShift Builder has a path traversal, allows command injection in privileged BuildContainerCVE-2024-45496Mediumgithub.com/openshift/openshift-controller-manager: OpenShift Controller Manager Improper Privilege ManagementCVE-2024-45041Highgithub.com/external-secrets/external-secrets: External Secrets Operator vulnerable to privilege escalationCVE-2024-8572Mediumgithub.com/gouniverse/cms: Gouniverse GoLang CMS vulnerable to Cross-site ScriptingCVE-2022-46156Mediumgithub.com/grafana/synthetic-monitoring-agent/cmd/synthetic-monitoring-agent: Default installation of `synthetic-monitoring-agent` exposes sensitive informationCVE-2022-24797Mediumgithub.com/pomerium/pomerium: Exposure of debug and metrics endpoints in Pomerium

Stop the waste.
Protect your environment with Kodem.