34,279 Entries 2,247 Sources 5 Verticals Last sync 12 minutes Live
Dashboard/Security
Sicherheit

Security

All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.

Sort: Newest Severity
CVE / GHSAItemVerticalSeverityDate
CVE-2025-32386 Source
A vulnerability in Helm allows attackers to exhaust all available memory and crash the application by using specially crafted chart archive files that expand dramatically when decompressed.
Helm OS & platform Medium 07.06.2026
CVE-2025-32387 Source
A vulnerability in Helm allows specially crafted JSON Schema files within charts to cause a stack overflow that can crash the application.
Helm OS & platform Medium 07.06.2026
CVE-2025-53547 Source
A vulnerability in Helm allows attackers to execute malicious code on the local system by using specially crafted Chart.yaml files and symbolic links to Chart.lock files when dependencies are updated.
Helm OS & platform High 07.06.2026
CVE-2025-55199 Source
A vulnerability in Helm allows malicious chart files to consume all available memory and crash the system through crafted JSON Schema references pointing to problematic files.
Helm OS & platform Medium 07.06.2026
CVE-2025-55198 Source
A vulnerability in Helm causes the application to crash when certain YAML configuration files contain invalid or empty values, affecting the tool's availability.
Helm OS & platform Medium 07.06.2026
CVE-2026-35206 Source
A vulnerability in Helm, a Kubernetes package manager, allows specially crafted charts to write files to the wrong directory during extraction, potentially overwriting existing files in the target location.
Helm OS & platform Medium 07.06.2026
CVE-2026-35205 Source
Helm, a package manager for Kubernetes, fails to properly verify plugin signatures in versions 4.0.0 to 4.1.3 and installs unsigned plugins despite enabled signature verification, allowing malicious plugins to execute arbitrary code.
Helm OS & platform Critical 07.06.2026
CVE-2026-35204 Source
A security vulnerability in Helm (Kubernetes package manager) allows malicious plugins to overwrite arbitrary files on the system, potentially compromising the entire system.
Helm OS & platform High 07.06.2026
CVE-2020-15257 Source
A vulnerability in containerd allows malicious containers with root privileges to start new processes with elevated privileges when running in the same network namespace as the shim.
containerd OS & platform Medium 07.06.2026
CVE-2020-15157 Source
A vulnerability in containerd version 1.2.x allows attackers to steal registry credentials by publishing malicious container images with special URLs that trick containerd into sending authentication data to attacker-controlled servers.
containerd OS & platform Medium 07.06.2026
CVE-2021-21334 Source
A bug in containerd's CRI implementation can cause containers using the same image to receive incorrect environment variables, potentially sharing sensitive information between containers with different security contexts.
containerd OS & platform Medium 07.06.2026
CVE-2021-32760 Source
A bug in containerd allows specially crafted container images to modify file permissions of existing files on the host system, potentially blocking access for legitimate users or widening access to others.
containerd OS & platform Medium 07.06.2026
CVE-2021-41103 Source
A permission flaw in containerd allowed regular Linux users to access container directories and execute programs with elevated privileges or read and modify files.
containerd OS & platform Medium 07.06.2026
GHSA-5j5w-g665-5m35 Source
Containerd versions before 1.4.12 and 1.5.8 trust HTTP Content-Type headers when loading container images, allowing the same image digest to be interpreted differently and compromising the uniqueness of image identification.
containerd OS & platform Medium 07.06.2026
CVE-2021-43816 Source
A vulnerability in containerd allows containers on Linux systems with SELinux to relabel arbitrary host files through specially configured bind mounts, gaining full read/write access to those files.
containerd OS & platform High 07.06.2026
CVE-2022-23648 Source
A flaw in containerd allows containers with specially crafted configurations to access arbitrary files on the host system, potentially bypassing security policies and exposing sensitive information.
containerd OS & platform Medium 07.06.2026
CVE-2022-24769 Source
A bug in containerd caused containers to start with unusual Linux permissions, allowing programs inside containers to gain additional system privileges beyond what was intended.
containerd OS & platform Low 07.06.2026
CVE-2022-31030 Source
A bug in containerd allows programs inside containers to consume unlimited memory when using the ExecSync function, potentially exhausting all available system memory and denying service to other legitimate workloads.
containerd OS & platform Medium 07.06.2026
CVE-2022-23471 Source
A bug in containerd's CRI implementation allows users to exhaust host memory by causing a goroutine memory leak when faulty commands are executed.
containerd OS & platform Medium 07.06.2026
CVE-2023-25173 Source
A bug in containerd causes supplementary user groups to be improperly set up in containers, potentially allowing attackers with direct container access to bypass group restrictions and gain access to sensitive information.
containerd OS & platform Medium 07.06.2026
CVE-2023-25153 Source
A vulnerability in containerd allows attackers to cause denial-of-service attacks through maliciously crafted container images with large files, as there was no size limit when importing certain files during image processing.
containerd OS & platform Medium 07.06.2026
GHSA-7ww5-4wqc-m92c Source
Containerd containers can access hardware power consumption data by default, allowing attackers to bypass security features like encryption by analyzing power usage patterns.
containerd OS & platform Medium 07.06.2026
CVE-2024-25621 Source
Containerd creates important directories with overly permissive access rights, allowing local users on the host to access container metadata and Kubernetes volumes, potentially leading to privilege escalation.
containerd OS & platform Medium 07.06.2026
CVE-2024-40635 Source
A bug in containerd causes containers with very large user IDs to run as root user due to a number overflow, bypassing security policies that require non-root execution.
containerd OS & platform Medium 07.06.2026
CVE-2025-64329 Source
A bug in containerd's CRI Attach function causes memory leaks through improperly terminated goroutines. Repeated kubectl attach commands can exhaust the host's memory, potentially slowing down or crashing the system.
containerd OS & platform Medium 07.06.2026
CVE-2025-47291 Source
A bug in containerd causes usernamespaced containers to bypass Kubernetes resource limits by not being placed under the proper control group hierarchy, potentially leading to denial of service of the Kubernetes node.
containerd OS & platform Medium 07.06.2026
CVE-2025-47290 Source
A vulnerability in containerd version 2.1.0 allows malicious container images to arbitrarily modify or create files on the host system during image download operations.
containerd OS & platform Critical 07.06.2026
CVE-2026-46680 Source
A bug in containerd causes containers with large numeric user IDs to incorrectly run as root, allowing security restrictions to be bypassed.
containerd OS & platform Medium 07.06.2026
CVE-2020-15113 Source
etcd, a distributed database, creates certain directories with restricted permissions but fails to verify that existing directories have these secure permissions, potentially allowing unintended data access.
etcd OS & platform Medium 07.06.2026
CVE-2020-15112 Source
A vulnerability in etcd allows an invalid index to be used when reading WAL entries, which can cause etcd nodes to crash during the consensus process.
etcd OS & platform Medium 07.06.2026
CVE-2020-15106 Source
A vulnerability in etcd allows attackers to create malicious WAL files with extremely large frame sizes that can crash the system when other cluster participants attempt to process them.
etcd OS & platform Medium 07.06.2026
GHSA-vjg6-93fv-qv64 Source
A vulnerability in etcd causes incomplete logging of authentication failures when users without passwords attempt to log in, making security monitoring more difficult.
etcd OS & platform Low 07.06.2026
GHSA-pm3m-32r3-7mfh Source
A vulnerability in etcd allows negative values for data retention, causing the service to enter an infinite loop that consumes excessive CPU and floods logs.
etcd OS & platform Low 07.06.2026
GHSA-9gp7-6833-wv89 Source
A vulnerability in etcd causes the service to crash when a negative cluster size is provided during service discovery.
etcd OS & platform Low 07.06.2026
GHSA-5x4g-q5rc-36jp Source
The etcd database supports insecure encryption methods for TLS connections, which could weaken communication security.
etcd OS & platform Low 07.06.2026
CVE-2020-15115 Source
The etcd database does not validate user password length, allowing extremely short passwords like single characters, which makes it easier for attackers to guess or brute-force crack user credentials.
etcd OS & platform Medium 07.06.2026
GHSA-528j-9r78-wffx Source
etcd stores user credentials like passwords unencrypted in WAL log files on disk, potentially exposing sensitive login information if these files are not properly secured.
etcd OS & platform Low 07.06.2026
CVE-2020-15114 Source
A vulnerability in the etcd gateway allows configuring the gateway address as an endpoint, creating an infinite loop that exhausts all available file descriptors and crashes the service.
etcd OS & platform High 07.06.2026
GHSA-j86v-2vjr-fg8f Source
The etcd gateway component incompletely validates endpoints and allows connections to servers without TLS encryption through HTTPS URLs, potentially leading to insecure connections.
etcd OS & platform Medium 07.06.2026
CVE-2020-15136 Source
A vulnerability in etcd's gateway feature causes TLS authentication to only be performed for DNS SRV endpoints but not for manually specified endpoints, potentially allowing insecure connections.
etcd OS & platform Medium 07.06.2026
GHSA-h8g9-6gvh-5mrc Source
A vulnerability in etcd's gateway component causes authentication settings of endpoints to not be properly validated, potentially allowing unauthorized access.
etcd OS & platform Low 07.06.2026
CVE-2023-32082 Source
A vulnerability in etcd allows users to view key names through the LeaseTimeToLive API even without read permissions, leading to unintended information disclosure in authentication-enabled clusters.
etcd OS & platform Low 07.06.2026
CVE-2026-33413 Source
A vulnerability in etcd allows unauthorized users to bypass authentication and authorization checks to call certain functions, enabling them to view cluster topology, disrupt services, or permanently delete data.
etcd OS & platform Medium 07.06.2026
CVE-2026-33343 Source
A vulnerability in etcd allows authenticated users to bypass access controls through nested transactions and access all stored data, even though they should only have restricted permissions.
etcd OS & platform Low 07.06.2026
CVE-2026-44283 Source
A vulnerability in etcd allows authenticated users to bypass RBAC permission checks and gain unauthorized access to data or attach leases by using specific transaction operations.
etcd OS & platform Low 07.06.2026
CVE-2024-31449 Source
A security vulnerability in Valkey allows authenticated users to cause a buffer overflow through specially crafted Lua scripts, potentially leading to remote code execution.
Valkey OS & platform High 07.06.2026
CVE-2024-31227 Source
A vulnerability in Valkey allows authenticated users with sufficient privileges to create malformed ACL selectors that cause server crashes and denial of service when accessed.
Valkey OS & platform Medium 07.06.2026
CVE-2024-31228 Source
A vulnerability in the Valkey database allows authenticated users to crash the service using specially crafted, extremely long text patterns, resulting in a denial-of-service attack.
Valkey OS & platform Medium 07.06.2026
CVE-2025-21605 Source
A vulnerability in the Valkey database allows unauthenticated attackers to consume unlimited memory by causing output buffers to grow indefinitely, leading to server crashes or memory exhaustion.
Valkey OS & platform High 07.06.2026
CVE-2025-49844 Source
A vulnerability in the Valkey database allows authenticated users to trigger memory corruption through specially crafted Lua scripts, potentially enabling remote code execution on the server.
Valkey OS & platform High 07.06.2026