Linuxfoundation
169 known vulnerabilities
Top Products
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local infor
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnera
PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `wei
sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-
EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequen
Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below,
Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary
Rekor is a software supply chain transparency log. In versions 1.4.3 and below, the entry implementation can panic on at
Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default impl
EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated
EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes`
EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has b
EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminat
EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol.
EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse
EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates
EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by
EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors
EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermet
EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to
Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed t
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by renderin
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering t
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass beca
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users A
An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted reques
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can r
The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrato
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrato
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard l
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks
The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveragin
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/
Frequently Asked Questions
How many CVEs affect Linuxfoundation?
Linuxfoundation has 169 CVE records in our database, including 19 critical and 64 high severity vulnerabilities.
What are the most severe Linuxfoundation vulnerabilities?
Linuxfoundation has 19 critical severity (CVSS 9.0+) and 64 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Linuxfoundation vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Linuxfoundation products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Linuxfoundation Vulnerabilities
CyberStrike scans your infrastructure for Linuxfoundation vulnerabilities and provides real-time remediation guidance.
Get Started