Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Weave

First CVE: Jun 3, 2020Active for: 6 yearsTotal CVEs: 10
33.2
VTI Score
Medium

Weave develops a focused suite of GitOps automation and infrastructure-management tools, including Weave GitOps and related controller and agent components, that orchestrate application deployment and configuration across cloud environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes centered on sensitive-information exposure, OS command injection, and cleartext transmission—reflecting the elevated privileges and secret-handling demands of deployment automation platforms. Defenders should prioritize tracking this vendor's security updates and audit GitOps pipeline configurations for credential exposure and command-injection risks; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Weave over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2020
6 years ago
Most Recent CVE
Apr 12, 2024
833 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-35975CRITICAL
The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the exte
Aug 18, 20229.829NONO
CVE-2020-35464CRITICAL
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may all
Dec 15, 20209.829NONO
CVE-2022-31098HIGH
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave
Jun 27, 20227.526NONO
CVE-2022-23508HIGH
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could al
Jan 9, 20237.825NONO
CVE-2022-35976CRITICAL
The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A specially crafted kubeconfig leads to arbitrary code execution on be
Aug 18, 20229.824NONO
CVE-2020-26278HIGH
Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts and enables their automatic discovery. Weave Net before vers
Jan 20, 20218.024NONO
CVE-2024-25545HIGH
An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component.
Apr 12, 20247.822NONO
CVE-2022-23509MEDIUM
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps run has a local S3 bucket which
Jan 9, 20236.021NONO
CVE-2023-34236MEDIUM
Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerability has been identified in Weave
Jul 14, 20236.519NONO
CVE-2020-11091MEDIUM
In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake
Jun 3, 20205.817NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
40%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (30.0%)
Network6 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (10.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (40.0%)
High2 (20.0%)
None4 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Weave.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Weave — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Weave's Products

View all 2 CNAs →

Top CWEs