KongCVEs & Vulnerabilities
2 CVEs affecting Kong products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
inf08 13kong alpine docker image 1
CVE-2020-35189CRITICAL
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
17 Dec 2020
9.8
CVSS
CVE-2012-6572MEDIUM
Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary name.
21 Jun 2013
4.3
CVSS
← PrevPage 1 / 1Next →