Ville Vesilehto
15 exploits
Active since Mar 2025
Argo Workflows < 3.7.14/4.0.5 templateReferencing - Strict Mode Bypass
CVSS 8.1
Kyverno Controller Denial of Service via forEach Mutation Panic
CVSS 7.7
Kyverno Controller Denial of Service via forEach Mutation Panic
CVSS 7.7
opa-envoy-plugin <1.13.2-envoy-2 - Auth Bypass
expr < 1.17.0 - Denial of Service via Unbounded Input Expression
CVSS 7.5
beego < 2.3.6 - Cross-Site Scripting via RenderForm Function
CVSS 9.3
cpp-httplib <0.20.1 - Memory Corruption
CVSS 7.5
Kyverno < 1.14.2 - Denial of Service via JMESPath Variable Substitution
CVSS 7.7
CoreDNS < 1.12.2 - Unauthenticated Denial of Service via Unbounded QUIC Stream Goroutines
CVSS 7.5
cpp-httplib <0.20.1 - Memory Corruption
CVSS 8.8
Argo CD <2.14.19, 3.1.7, 3.0.18 - Info Disclosure
CVSS 6.5
CoreDNS 1.2.0-1.12.3 - Denial of Service via TTL Confusion in etcd Plugin
CVSS 7.1
CoreDNS < 1.14.0 - Unauthenticated Denial of Service via Resource Exhaustion
CVSS 7.5
Kyverno < 1.15.3 - Authenticated Server-Side Request Forgery via Namespaced Policy apiCall
CVSS 9.9
Kyverno < 1.15.3 - Denial of Service via Policy Engine Context Variable Amplification
CVSS 7.7