Vulnerabilities

Last updated 40 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
github.com/argoproj/argo-cd/v2 Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL High Risk 8.8 5 hours ago 5 hours ago
github.com/argoproj/argo-cd/v3 Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL High Risk 8.8 5 hours ago 5 hours ago
github.com/argoproj/argo-cd Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation High Risk 7.3 4 months ago 29 days ago
github.com/argoproj/argo-cd/v2 Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation High Risk 7.3 4 months ago 29 days ago
github.com/argoproj/argo-cd/v3 Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation High Risk 7.3 4 months ago 29 days ago
github.com/argoproj/argo-cd/v3 Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations Medium Risk 6.3 4 months ago 29 days ago
github.com/argoproj/argo-cd/v3 ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction Critical 9.6 5 months ago 29 days ago
github.com/argoproj/argo-cd/v2 Argo CD's Project API Token Exposes Repository Credentials Critical 9.9 1 year ago 29 days ago
github.com/argoproj/argo-cd/v3 Argo CD's Project API Token Exposes Repository Credentials Critical 9.9 1 year ago 29 days ago
github.com/argoproj/argo-cd Argo CD does not scrub secret values from patch errors Medium Risk 6.8 1 year ago 29 days ago
github.com/argoproj/argo-cd/v2 Argo CD does not scrub secret values from patch errors Medium Risk 6.8 1 year ago 29 days ago
github.com/argoproj/argo-cd Argo-cd authenticated users can enumerate clusters by name Medium Risk 4.3 2 years ago 29 days ago
github.com/argoproj/argo-cd/v2/server Unauthenticated Access to sensitive settings in Argo CD Medium Risk 5.3 2 years ago 29 days ago
github.com/argoproj/argo-cd Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment High Risk 7.5 2 years ago 29 days ago
github.com/argoproj/argo-cd/v2 Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment High Risk 7.5 2 years ago 29 days ago
github.com/argoproj/argo-cd github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability High Risk 8.3 2 years ago 29 days ago
github.com/argoproj/argo-cd/v2 github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability High Risk 8.3 2 years ago 29 days ago
github.com/argoproj/argo-cd/v2 Argo CD leaks repository credentials in user-facing error messages and in logs Medium Risk 6.3 3 years ago 29 days ago
github.com/argoproj/argo-cd Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server Medium Risk 5.0 3 years ago 29 days ago
github.com/argoproj/argo-cd/v2 Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server Medium Risk 5.0 3 years ago 29 days ago
github.com/argoproj/argo-cd Users with any cluster secret update access may update out-of-bounds cluster secrets Critical 9.1 3 years ago 29 days ago
github.com/argoproj/argo-cd JWT audience claim is not verified Critical 9.0 3 years ago 29 days ago
github.com/argoproj/argo-cd/v2 Controller reconciles apps outside configured namespaces when sharding is enabled High Risk 8.5 3 years ago 29 days ago
github.com/argoproj/argo-cd Argo CD allows cross-site scripting on repositories page Critical 9.0 1 year ago 29 days ago
github.com/argoproj/argo-cd/v2 Argo CD allows cross-site scripting on repositories page Critical 9.0 1 year ago 29 days ago
github.com/argoproj/argo-cd/v3 Argo CD allows cross-site scripting on repositories page Critical 9.0 1 year ago 29 days ago
github.com/argoproj/argo-cd ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache Critical 9.0 2 years ago 29 days ago
github.com/argoproj/argo-cd/v2 ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache Critical 9.0 2 years ago 29 days ago
github.com/argoproj/argo-cd Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint High Risk 7.5 2 years ago 29 days ago
github.com/argoproj/argo-cd/v2 Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint High Risk 7.5 2 years ago 29 days ago
github.com/argoproj/argo-cd/v2 Repository Credentials Race Condition Crashes Argo CD Server Medium Risk 6.5 1 year ago 1 month ago
github.com/argoproj/argo-cd/v3 Repository Credentials Race Condition Crashes Argo CD Server Medium Risk 6.5 1 year ago 1 month ago
github.com/argoproj/argo-cd Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Unknown 11 months ago 1 month ago
github.com/argoproj/argo-cd/v2 Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Unknown 11 months ago 1 month ago
github.com/argoproj/argo-cd/v3 Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd Unknown 11 months ago 1 month ago
github.com/argoproj/argo-cd/v2 Argo CD's API server does not enforce project sourceNamespaces Medium Risk 4.8 2 years ago 2 months ago
github.com/argoproj/argo-cd The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd Unknown 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd Unknown 2 years ago 2 months ago
github.com/argoproj/argo-cd Users with `create` but not `override` privileges can perform local sync Medium Risk 6.4 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 Users with `create` but not `override` privileges can perform local sync Medium Risk 6.4 2 years ago 2 months ago
github.com/argoproj/argo-cd Cross-site scripting on application summary component Critical 9.0 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 Cross-site scripting on application summary component Critical 9.0 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 Out of memory crash from malicious Helm registry in github.com/argoproj/argo-cd/v2 Unknown 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 Bypassing Rate Limit and Brute Force Protection Using Cache Overflow Medium Risk 5.4 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss Critical 9.8 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences Medium Risk 6.5 2 years ago 2 months ago
github.com/argoproj/argo-cd Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Unknown 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2 Unknown 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 The Argo CD web terminal session does not handle the revocation of user permissions properly Medium Risk 4.7 2 years ago 2 months ago
github.com/argoproj/argo-cd/v2 Brute force protection bypass in github.com/argoproj/argo-cd/v2 Unknown 2 years ago 2 months ago