Vulnerabilities

Summary — last 7 days

New vulnerabilities2,623▼ 237 vs. last week
Critical / high1,384▲ 151 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)56▼ 473 vs. last week
–

11 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.7)0.61%—Uber KrakenAI9/16/20269/24/2026
Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend…
DeferredCritical (9)0.18%—Eclipse AeriosAIKrakendAI9/2/20269/3/2026
In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart configuration. This setting disables TLS…
DeferredCritical (9.1)0.24%—KrakenAI8/18/20269/24/2026
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply substituted content with forged CRC32…
DeferredLow (1.3)0.41%—Krakend-ceAIKrakend-eeAI2/25/20266/17/2026
Improper Resource Shutdown or Release vulnerability in KrakenD, SLU KrakenD-CE (CircuitBreaker modules), KrakenD, SLU KrakenD-EE (CircuitBreaker modules). This issue affects KrakenD-CE: before 2.13.1; KrakenD-EE: before 2.12.5.
AnalyzedCritical (9.8)0.55%—Axosoft Gitkraken Desktop8/4/20256/17/2026
The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode,…
DeferredMedium (4.3)0.65%—Kraken.io Image OptimizerAI12/9/20246/17/2026
Missing Authorization vulnerability in Karim Salman Kraken.io Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kraken.io Image Optimizer: from n/a through 2.6.7.
ModifiedHigh (7.8)1.3%—Gitkraken Gitlens11/28/20236/17/2026
An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Visual Studio Codes workspace trust component.
ModifiedMedium (6.5)0.68%—Kraken.io Image Optimizer2/1/20236/17/2026
The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset image optimizations.
ModifiedHigh (7.5)0.80%—Uber Kraken1/20/20236/17/2026
kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
ModifiedHigh (8.8)0.36%—Kraken.io Image Optimizer9/23/20226/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kraken.io Image Optimizer plugin <= 2.6.5 at WordPress.
ModifiedMedium (4.3)0.57%—KrakendLuraproject Lura8/1/20226/17/2026
Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulnerability does not affect KrakenD itself, but the consumed backend…