Search

Found 16,653 results in 891ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-31672 unknown debian debian 1y ago Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
CVE-2025-29480 unknown debian debian sles 1y ago Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invali…
CVE-2025-3136 unknown debian debian 1y ago A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAlloc…
CVE-2025-31130 unknown FIX debian debian 1y ago gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxid…
CVE-2025-3121 unknown debian debian 1y ago A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is …
CVE-2025-27556 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.L…
CVE-2025-3001 unknown FIX debian debian 1y ago A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approac…
CVE-2025-3000 unknown debian debian 1y ago A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on…
CVE-2025-2999 unknown FIX debian debian 1y ago A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Atta…
CVE-2025-2998 unknown FIX debian debian 1y ago A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory c…
CVE-2025-2953 unknown debian debian 1y ago A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of servic…
CVE-2025-2783 unknown 2.5 KEVEXPFIX debian debian 1y ago Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability…
CVE-2025-30474 unknown FIX debian debian sles 1y ago Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-27553 unknown FIX debian debian sles 1y ago Apache Commons VFS Has Relative Path Traversal Vulnerability
CVE-2020-36843 unknown FIX slesdebian debian 1y ago Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check
CVE-2025-2149 unknown debian debian 1y ago A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of t…
CVE-2025-2148 unknown debian debian 1y ago A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component T…
CVE-2025-26699 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-ser…
CVE-2025-4432 unknown FIX debian debian 1y ago Ring: some aes functions may panic when overflow checking is enabled in ring in github.com/briansmith/ring
CVE-2025-27426 unknown FIX debian debian 1y ago Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.
CVE-2025-1942 unknown FIX debian debian 1y ago When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird…
CVE-2025-1941 unknown FIX debian debian 1y ago Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firef…
CVE-2025-1940 unknown FIX debian debian 1y ago A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue onl…
CVE-2025-26791 unknown FIX slesdebian debian 1y ago DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
CVE-2025-25193 unknown FIX slesdebian debian 1y ago Denial of Service attack on windows app using Netty
CVE-2025-25188 unknown FIX debian debian 1y ago Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DN…
CVE-2025-24970 unknown FIX slesdebian debian 1y ago SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
CVE-2024-57699 unknown FIX debian debian 1y ago Netplex Json-smart Uncontrolled Recursion vulnerability
CVE-2025-0411 unknown 1.5 KEVFIX debian debian sles 1y ago 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2025-24374 unknown FIX debian debian 1y ago Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
CVE-2025-24814 unknown FIX debian debian 1y ago Apache Solr vulnerable to Execution with Unnecessary Privileges
CVE-2024-52012 unknown FIX debian debian 1y ago Apache Solr Relative Path Traversal vulnerability
CVE-2025-22620 unknown FIX debian debian 1y ago gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them ap…
CVE-2024-5138 unknown FIX debian debian 1y ago The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse …
CVE-2023-0482 unknown debian debian 1y ago Insecure Temporary File in RESTEasy
CVE-2024-56374 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a p…
CVE-2024-52046 unknown FIX debian debian 2y ago Apache MINA Deserialization RCE Vulnerability
CVE-2024-56334 unknown FIX debian debian 2y ago systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` f…
CVE-2024-38819 unknown debian debian 2y ago Spring Framework Path Traversal vulnerability
CVE-2024-12801 unknown slesdebian debian 2y ago QOS.CH logback-core Server-Side Request Forgery vulnerability
CVE-2024-12798 unknown slesdebian debian google 2y ago QOS.CH logback-core Expression Language Injection vulnerability
CVE-2024-45338 unknown FIX debian debian sles 2y ago An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.
CVE-2024-45337 unknown FIX debian debian sles 2y ago Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerCo…
CVE-2024-6156 unknown FIX debian debian 2y ago Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
CVE-2024-6219 unknown FIX debian debian 2y ago Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
CVE-2024-55601 unknown FIX debian debian 2y ago Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks…
CVE-2024-55565 unknown FIX debian debian 2y ago nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
CVE-2024-53908 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subje…
CVE-2024-53907 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack…
CVE-2024-38829 unknown debian debian 2y ago Spring LDAP data exposure vulnerability
CVE-2024-53981 unknown FIX slesdebian debian 2y ago python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of the first boundary and any tailing bytes after the…
CVE-2024-53990 unknown debian debian 2y ago AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
CVE-2024-36623 unknown FIX debian debian sles 2y ago moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application cr…
CVE-2024-36621 unknown FIX debian debian sles 2y ago moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function result…
CVE-2024-36620 unknown FIX debian debian 2y ago moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
CVE-2024-53916 unknown FIX debian debian 2y ago In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileg…
CVE-2024-44308 unknown 1.5 KEVFIX slesdebian debian 2y ago Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.
CVE-2024-52304 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request s…
CVE-2024-52303 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError…
CVE-2024-52318 unknown FIX slesdebian debian 2y ago Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97…
CVE-2024-52317 unknown FIX slesdebian debian 2y ago Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between us…
CVE-2024-52316 unknown FIX slesdebian debian 2y ago Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception dur…
CVE-2024-38828 unknown debian debian 2y ago Spring MVC controller vulnerable to a DoS attack
CVE-2023-4639 unknown FIX debian debian 2y ago Undertow incorrectly parses cookies
CVE-2024-51996 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted i…
CVE-2024-47535 unknown FIX slesdebian debian 2y ago Denial of Service attack on windows app using netty
CVE-2024-5535 critical 9.1 9.1 FIX rhel rocky sles 2y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-38612 critical 9.8 9.8 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defin…
CVE-2024-47072 unknown FIX slesdebian debian 2y ago XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
CVE-2024-51504 unknown FIX debian debian 2y ago Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
CVE-2023-1973 unknown FIX debian debian 2y ago Undertow Denial of Service vulnerability
CVE-2023-1932 unknown debian debian 2y ago hibernate-validator Cross-site Scripting vulnerability
CVE-2024-51755 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property polic…
CVE-2024-51754 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of …
CVE-2024-51736 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory i…
CVE-2024-50345 unknown FIX debian debian 2y ago symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters t…
CVE-2024-50343 unknown FIX debian debian 2y ago symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metachar…
CVE-2024-50342 unknown FIX debian debian 2y ago symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, so…
CVE-2024-50341 unknown FIX debian debian 2y ago symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` define…
CVE-2024-50340 unknown FIX debian debian 2y ago symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any…
CVE-2024-51746 unknown FIX debian debian 2y ago Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are …
CVE-2024-48910 unknown FIX debian debian 2y ago DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
CVE-2024-48063 unknown debian debian 2y ago In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
CVE-2024-49760 unknown FIX debian debian 2y ago OpenRefine has a path traversal in LoadLanguageCommand
CVE-2024-47883 unknown FIX debian debian 2y ago Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
CVE-2024-47882 unknown FIX debian debian 2y ago OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project
CVE-2024-47881 unknown FIX debian debian 2y ago OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
CVE-2024-47880 unknown FIX debian debian 2y ago OpenRefine has a reflected cross-site scripting vulnerability (XSS) from POST request in ExportRowsCommand
CVE-2024-47879 unknown FIX debian debian 2y ago OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
CVE-2024-47878 unknown FIX debian debian 2y ago OpenRefine has a reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
CVE-2024-37383 unknown 2.5 KEVEXPFIX debian debian 2y ago RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.
CVE-2024-38820 unknown debian debian 2y ago Spring Framework DataBinder Case Sensitive Match Exception
CVE-2024-45217 unknown FIX debian debian 2y ago Insecure Default Initialization of Resource vulnerability in Apache Solr
CVE-2024-45216 unknown FIX debian debian 2y ago Improper Authentication vulnerability in Apache Solr
CVE-2024-47874 unknown FIX slesdebian debian 2y ago Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and buff…
CVE-2024-6763 unknown debian debian sles 2y ago Eclipse Jetty URI parsing of invalid authority
CVE-2024-8184 unknown FIX debian debian sles 2y ago Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
CVE-2024-6762 unknown FIX debian debian sles 2y ago Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
CVE-2024-9823 unknown FIX debian debian sles 2y ago Eclipse Jetty has a denial of service vulnerability on DosFilter
CVE-2024-28168 unknown FIX debian debian sles 2y ago Apache XML Graphics FOP XML External Entity Reference ('XXE') vulnerability