Search

Found 10,197 results in 4238ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-28956 high 8.0 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2011-10007 high 8.0 FIX sles rhel rocky 1y ago RHSA-2025:9605: perl-File-Find-Rule security update (Important)
CVE-2025-6019 high 8.0 FIX rhelarch arch rocky 1y ago RHSA-2025:9878: libblockdev security update (Important)
CVE-2025-49180 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. This issue leads to an integer overflow when computing the total size to allocat…
CVE-2025-49179 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length …
CVE-2025-49178 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial…
CVE-2025-49177 high 8.0 FIX rhel slesdebian debian 1y ago A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
CVE-2025-49176 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size …
CVE-2025-49175 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potenti…
CVE-2025-40908 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:9329: perl-YAML-LibYAML security update (Important)
CVE-2025-3891 medium 5.5 FIX rhel rockydebian debian 1y ago RHSA-2025:4597: mod_auth_openidc:2.3 security update (Moderate)
CVE-2025-37738 medium 5.5 FIX rhel rocky sles 1y ago Moderate: kernel security update
CVE-2025-23150 medium 5.5 FIX rhel rocky sles 1y ago Moderate: kernel security update
CVE-2025-22104 medium 5.5 FIX rhel sles rocky 1y ago Moderate: kernel security update
CVE-2025-21919 medium 5.5 FIX rhel rocky sles 1y ago Moderate: kernel security update
CVE-2025-21883 medium 5.5 FIX rhel sles rocky 1y ago Moderate: kernel security update
CVE-2025-5473 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:9165: gimp:2.8 security update (Important)
CVE-2025-48798 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:9165: gimp:2.8 security update (Important)
CVE-2025-48797 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:9165: gimp:2.8 security update (Important)
CVE-2025-4404 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:9188: idm:DL1 security update (Important)
CVE-2025-6170 low 2.5 2.5 FIX arch arch slesdebian debian redhatxmlsoft 1y ago A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, …
CVE-2025-48734 high 8.0 FIX rheldebian debian sles 1y ago Important: apache-commons-beanutils security update
CVE-2025-37750 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-22126 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21999 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21979 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21969 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21963 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21961 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-47947 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8844: mod_security security update (Important)
CVE-2025-30399 high 8.0 rhel rocky 1y ago RHSA-2025:8815: .NET 9.0 security update (Important)
CVE-2022-49395 medium 5.5 FIX rocky slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: um: Fix out-of-bounds read in LDT setup syscall_stub_data() expects the data_count parameter to be the number of longs, not bytes…
CVE-2025-4802 medium 5.5 FIX rhel rockydebian debian 1y ago RHSA-2025:8686: glibc security update (Moderate)
CVE-2025-40907 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:8696: perl-FCGI:0.78 security update (Important)
CVE-2025-37943 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-37785 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-22055 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21997 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21926 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21920 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-4447 high 8.0 sles rhel 1y ago RHSA-2025:8431: java-1.8.0-ibm security update (Important)
CVE-2025-23167 high 8.0 FIX rhel rockyarch arch 1y ago A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers t…
CVE-2025-23166 high 8.0 FIX rhel rockyarch arch 1y ago RHSA-2025:8514: nodejs:20 security update (Important)
CVE-2025-23165 high 8.0 FIX rhel rockyarch arch 1y ago RHSA-2025:8514: nodejs:20 security update (Important)
CVE-2023-24824 medium 5.5 FIX rockydebian debian rhel 1y ago RHSA-2025:8427: pandoc security update (Moderate)
CVE-2020-16156 medium 5.5 FIX arch arch rocky sles 1y ago RHSA-2025:8432: perl-CPAN security update (Moderate)
CVE-2025-47905 high 8.0 FIX rhel rockydebian debian 1y ago Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to d…
CVE-2025-21764 high 7.8 7.8 FIX rhel rocky sles 1y ago Moderate: kernel security update
CVE-2022-3424 medium 5.5 FIX rhel slesdebian debian 1y ago Moderate: kernel security update
CVE-2025-5283 high 8.0 FIX rhel rockydebian debian 1y ago Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5269 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:8756: thunderbird security update (Important)
CVE-2025-5268 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort …
CVE-2025-5267 high 8.0 FIX rhel rockydebian debian 1y ago A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunder…
CVE-2025-5266 high 8.0 FIX rhel rockydebian debian 1y ago Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thu…
CVE-2025-5264 high 8.0 FIX rhel rockydebian debian 1y ago Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's …
CVE-2025-5263 high 8.0 FIX rhel rockydebian debian 1y ago Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Fir…
CVE-2025-32910 high 8.0 FIX rocky slesdebian debian 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-32909 high 8.0 FIX rocky slesdebian debian 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-3932 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:8756: thunderbird security update (Important)
CVE-2025-3909 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:8756: thunderbird security update (Important)
CVE-2025-3887 high 8.0 FIX rheldebian debian sles 1y ago RHSA-2025:8201: gstreamer1-plugins-bad-free security update (Important)
CVE-2025-3877 high 8.0 rhel rocky 1y ago RHSA-2025:8756: thunderbird security update (Important)
CVE-2025-3875 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:8756: thunderbird security update (Important)
CVE-2025-4948 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:8132: libsoup security update (Important)
CVE-2025-32914 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8132: libsoup security update (Important)
CVE-2025-32049 high 8.0 rhel rocky sles 1y ago RHSA-2025:8132: libsoup security update (Important)
CVE-2025-2784 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8132: libsoup security update (Important)
CVE-2025-21964 medium 5.5 FIX rhel sles rocky 1y ago Moderate: kernel security update
CVE-2025-4919 high 8.0 FIX rhel rockydebian debian 1y ago An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ES…
CVE-2025-4918 high 8.0 FIX rhel rockydebian debian 1y ago An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbi…
CVE-2025-47273 medium 5.5 FIX rhel rocky sles 1y ago Moderate: fence-agents security update
CVE-2025-4123 medium 6.1 7.1 EXPFIX rhel rocky sles grafana 1y ago Important: grafana security update
CVE-2025-37749 high 8.0 FIX rhel slesdebian debian 1y ago Important: kernel security update
CVE-2025-31257 medium 4.7 4.7 FIX rhel rockyarch arch apple 1y ago This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously…
CVE-2025-31205 high 8.0 FIX rhel rockyarch arch 1y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A malicious website may exfiltra…
CVE-2025-21966 high 8.0 FIX rhel slesdebian debian 1y ago Important: kernel security update
CVE-2025-21756 high 7.8 7.8 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2025-47287 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8254: pcs security update (Important)
CVE-2022-4055 medium 5.5 rhel slesdebian debian 1y ago Moderate: xdg-utils security update
CVE-2025-27832 medium 5.5 FIX rheldebian debian sles 1y ago Moderate: ghostscript security update
CVE-2025-26646 high 8.0 FIX rhel rockyalmalinux almalinux 1y ago RHSA-2025:7589: .NET 8.0 security update (Important)
CVE-2020-13790 medium 5.5 FIX rocky slesdebian debian 1y ago RHSA-2025:7540: libjpeg-turbo security update (Moderate)
CVE-2019-19012 medium 5.5 FIX rockydebian debian rhel 1y ago RHSA-2025:7539: ruby:2.5 security update (Moderate)
CVE-2025-71151 medium 5.5 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3_reconfigure() In smb3_reconfigure(), if smb3_sync_session_ctx_passwords() fails, th…
CVE-2025-68179 medium 5.5 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP As reported by Luiz Capitulino enabling HVO on s390 leads to reproducible crashe…
CVE-2025-46421 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:4560: libsoup security update (Important)
CVE-2025-46420 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:4560: libsoup security update (Important)
CVE-2025-32913 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-32911 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-32907 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-32906 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-3277 high 8.0 FIX rhel rocky sles 1y ago Important: nodejs:22 security update
CVE-2025-32053 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-32052 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-32050 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-3155 high 8.0 FIX rhel slesdebian debian 1y ago A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrat…
CVE-2025-31498 high 8.0 FIX rhel rockydebian debian 1y ago Important: nodejs:22 security update
CVE-2025-31492 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:3997: mod_auth_openidc:2.3 security update (Important)
CVE-2025-30472 medium 5.5 FIX rheldebian debian sles 1y ago Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.
CVE-2025-26465 medium 6.8 6.8 FIX rhel rocky sles openbsdnetappredhat 1y ago A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occur…