Skip to main content

Vendor archive

cloudark CVEs

Beta · best-effort

2 CVEs tagged to vendor cloudark0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-29955

Published Apr 13, 2026

The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` par…

CVSS 8.8 · High
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-29954

Published Mar 30, 2026

In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The fiel…

CVSS 7.6 · High
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1