Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Manifest/
  3. Manifest Cyber Manifest Platform

Manifest Cyber Manifest Platform

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 71 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Platform for securing software supply chain, AI models, and vendor software

by Manifest · manifestcyber.com · source ↗

Known CVEs (71)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2023-50726 ↗MEDIUM 6.42024

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an Application's manifests with locally-defi…

  • CVE-2023-46918 ↗MEDIUM 4.62023

    Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leverag…

  • CVE-2023-6862 ↗HIGH 8.82023

    A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 115.6 and Thunderbird < 115.6.

  • CVE-2023-36620 ↗MEDIUM 4.62023

    An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to ba…

  • CVE-2023-38552 ↗HIGH 7.52023

    When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementat…

  • CVE-2023-42471 ↗CRITICAL 9.82023

    The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.bro…

  • CVE-2023-40040 ↗MEDIUM 5.32023

    An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacker can start the camera feed via the com.cordovaplugincamerapreview.CameraActivit…

  • CVE-2023-40584 ↗MEDIUM 6.52023

    Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack v…

  • CVE-2023-39532 ↗CRITICAL 9.82023

    SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.1…

  • CVE-2023-35934 ↗MEDIUM 6.12023

    yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different ho…

  • CVE-2023-3027 ↗HIGH 7.82023

    The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on…

  • CVE-2023-33293 ↗MEDIUM 5.32023

    An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An a…

  • CVE-2022-4457 ↗MEDIUM 5.52023

    Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker could create a malicious mobile application which could…

  • CVE-2022-34471 ↗MEDIUM 6.52022

    When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, a…

  • CVE-2022-31691 ↗CRITICAL 9.82022

    Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39…

  • CVE-2022-31036 ↗MEDIUM 4.32022

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 are vulnerable to a symlink following bug allowing a malicious user with reposito…

  • CVE-2022-24904 ↗MEDIUM 4.32022

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.7.0 and prior to versions 2.1.15m 2.2.9, and 2.3.4 is vulnerable to a symlink following bug al…

  • CVE-2022-0675 ↗MEDIUM 5.62022

    In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist …

  • CVE-2022-21682 ↗HIGH 7.72022

    Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last …

  • CVE-2021-43388 ↗HIGH 7.52021

    Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the m…

  • …and 51 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Software Supply Chain Security products

see all →
  • Apiiro Deliver · Apiiro
  • Apiiro SSCS · Apiiro
  • Aqua Software Supply Chain Security · Aqua Security
  • BoostSecurity Cloud-speed Compliance · BoostSecurity
  • BoostSecurity Software Supply Chain Protection · BoostSecurity
  • CI/CD Security · Cycode
  • Chainguard Containers · Chainguard
  • Chainguard Libraries · Chainguard