Search

Found 18,360 results in 1155ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-45230 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via ve…
CVE-2024-47211 unknown FIX debian debian 2y ago In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when…
CVE-2024-47855 unknown FIX slesdebian debian 2y ago JSON-lib mishandles an unbalanced comment string
CVE-2024-47554 unknown FIX debian debian sles 2y ago Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
CVE-2024-47534 unknown FIX debian debian 2y ago go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", th…
CVE-2024-47175 low 3.5 EXPFIX rhel rockydebian debian 2y ago Low: cups security update
CVE-2024-38809 unknown debian debian 2y ago Spring Framework DoS via conditional HTTP request
CVE-2024-7254 unknown FIX slesdebian debian 2y ago protobuf-java has potential Denial of Service issue
CVE-2024-45492 critical 9.8 9.8 FIX rhel rockydebian debian libexpat_project 2y ago RHSA-2024:6989: expat security update (Moderate)
CVE-2024-45491 critical 9.8 9.8 FIX rhel rockydebian debian libexpat_project 2y ago RHSA-2024:8859: xmlrpc-c security update (Moderate)
CVE-2024-45801 unknown FIX debian debian 2y ago DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking ad…
CVE-2024-38816 unknown debian debian 2y ago Path traversal vulnerability in functional web frameworks
CVE-2024-45411 unknown FIX debian debian 2y ago Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability i…
CVE-2017-1000253 unknown 2.5 KEVEXPFIX slesdebian debian 2y ago Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.
CVE-2016-3714 unknown 2.5 KEVEXPFIX debian debian 2y ago ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code v…
CVE-2024-45405 unknown FIX slesdebian debian 2y ago `gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a…
CVE-2024-45159 critical 9.8 9.8 FIX debian debian trustedfirmware 2y ago An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in…
CVE-2024-45158 critical 9.8 9.8 FIX debian debian trustedfirmware 2y ago An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest…
CVE-2024-37371 critical 9.1 9.1 FIX rhelarch arch rocky mit 2y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-45305 unknown FIX slesdebian debian 2y ago gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to find the path of a configuration file that belongs to the `git` installation its…
CVE-2024-43805 unknown FIX slesdebian debian 2y ago jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious n…
CVE-2024-7965 unknown 1.5 KEVFIX debian debian 2y ago Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-43788 unknown FIX slesdebian debian 2y ago Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. Th…
CVE-2024-7971 unknown 1.5 KEVFIX debian debian 2y ago Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-38807 unknown debian debian 2y ago Signature forgery in Spring Boot's Loader
CVE-2024-7885 unknown FIX debian debian 2y ago Undertow vulnerable to Race Condition
CVE-2024-38808 unknown debian debian 2y ago Spring Framework vulnerable to Denial of Service
CVE-2024-35845 critical 9.1 9.1 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-42367 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain files with compressed variants (`.g…
CVE-2024-42005 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a c…
CVE-2024-41991 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service…
CVE-2024-41990 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs wit…
CVE-2024-41989 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number i…
CVE-2024-3596 critical 9.0 9.0 FIX rhel rockydebian debian freeradiusbroadcom 2y ago RHSA-2024:8860: krb5 security update (Important)
CVE-2024-41110 unknown FIX debian debian sles 2y ago Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypas…
CVE-2024-29069 unknown FIX debian debian 2y ago In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic …
CVE-2024-29068 unknown FIX debian debian 2y ago In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular fil…
CVE-2024-1724 unknown FIX debian debian 2y ago In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatica…
CVE-2024-40767 unknown FIX debian debian 2y ago In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a desc…
CVE-2024-4418 low 2.5 FIX rhel rocky sles 2y ago RHSA-2024:4351: virt:rhel and virt-devel:rhel security and bug fix update (Low)
CVE-2024-4032 low 2.5 FIX rhel rocky sles 2y ago Low: python3 security update
CVE-2024-25638 unknown FIX debian debian 2y ago DNSJava DNSSEC Bypass
CVE-2024-40644 unknown FIX debian debian 2y ago gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows…
CVE-2022-48833 unknown FIX slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: btrfs: skip reserved bytes warning on unmount after log cleanup failure After the recent changes made by commit c2e39305299f01 ("…
CVE-2022-29946 unknown FIX debian debian 2y ago NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one sc…
CVE-2024-39614 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings contain…
CVE-2024-39330 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicati…
CVE-2024-39329 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing a…
CVE-2024-38875 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of br…
CVE-2024-38372 unknown FIX debian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the N…
CVE-2024-3653 unknown FIX debian debian 2y ago Undertow Missing Release of Memory after Effective Lifetime vulnerability
CVE-2024-5971 unknown FIX debian debian 2y ago Undertow Denial of Service vulnerability
CVE-2024-35960 critical 9.1 9.1 FIX rhel rocky sles 2y ago Moderate: kernel security and bug fix update
CVE-2024-39689 unknown FIX slesdebian debian 2y ago Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.…
CVE-2024-32498 unknown FIX debian debian 2y ago An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 …
CVE-2022-30636 unknown FIX debian debian 2y ago httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows uses a di…
CVE-2023-2953 low 2.5 FIX rocky slesdebian debian 2y ago RHSA-2024:4264: openldap security update (Low)
CVE-2024-58261 unknown FIX slesdebian debian 2y ago The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupp…
CVE-2020-13965 unknown 1.5 KEVFIX debian debian 2y ago Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.
CVE-2024-6162 unknown FIX debian debian 2y ago Undertow's url-encoded request path information can be broken on ajp-listener
CVE-2024-38595 unknown FIX slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix peer devlink set for SF representor devlink port The cited patch change register devlink flow, and neglect to refle…
CVE-2024-4577 unknown 2.5 KEVEXPFIX slesdebian debian 2y ago PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
CVE-2024-35241 unknown FIX debian debian sles 2y ago Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing …
CVE-2024-35242 unknown FIX debian debian sles 2y ago Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch na…
CVE-2024-37568 unknown FIX slesdebian debian 2y ago lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (…
CVE-2024-5187 unknown FIX slesdebian debian 2y ago onnx allows Arbitrary File Overwrite in download_model_with_test_data
CVE-2024-5629 low 2.5 FIX rocky slesdebian debian 2y ago RHSA-2025:8419: python36:3.6 security update (Low)
CVE-2015-2309 unknown FIX debian debian 2y ago Symfony has unsafe methods in the Request class
CVE-2024-5274 unknown 1.5 KEVFIX debian debian 2y ago Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2024-35197 unknown FIX slesdebian debian 2y ago gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary…
CVE-2024-35186 unknown FIX slesdebian debian 2y ago gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned…
CVE-2020-21710 low 2.5 FIX slesdebian debian rocky 2y ago RHSA-2024:2966: ghostscript security update (Low)
CVE-2024-4947 unknown 1.5 KEVFIX debian debian 2y ago Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2024-35935 low 3.3 3.3 FIX slesdebian debian linux-kernel 2y ago In the Linux kernel, the following vulnerability has been resolved: btrfs: send: handle path ref underflow in header iterate_inode_ref() Change BUG_ON to proper error handling if building the path …
CVE-2024-4761 unknown 1.5 KEVFIX debian debian 2y ago Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVE-2024-35176 low 2.5 FIX rocky slesdebian debian 2y ago RHSA-2024:5338: pcs security update (Low)
CVE-2024-30172 unknown FIX debian debian sles 2y ago Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
CVE-2024-30171 unknown FIX debian debian sles 2y ago Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
CVE-2024-29857 unknown FIX debian debian sles 2y ago Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
CVE-2024-4671 unknown 1.5 KEVFIX debian debian 2y ago Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. …
CVE-2024-25629 low 2.5 FIX rheldebian debian rocky 2y ago RHSA-2024:4249: c-ares security update (Low)
CVE-2024-34447 unknown FIX debian debian sles 2y ago Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
CVE-2024-31636 unknown debian debian 2y ago LIEF obtain sensitive information via the name parameter
CVE-2024-30251 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp serv…
CVE-2024-32114 unknown FIX debian debian 2y ago Apache ActiveMQ's default configuration doesn't secure the API web context
CVE-2024-31573 unknown FIX debian debian 2y ago XMLUnit for Java has Insecure Defaults when Processing XSLT Stylesheets
CVE-2024-27053 critical 9.1 9.1 FIX slesdebian debian linux-kernel 2y ago In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix RCU usage in connect path With lockdep enabled, calls to the connect function from cfg802.11 layer lead to th…
CVE-2023-6918 low 2.5 FIX rhel rocky sles 2y ago RHSA-2024:3233: libssh security update (Low)
CVE-2023-6004 low 2.5 FIX rhel rocky sles 2y ago RHSA-2024:3233: libssh security update (Low)
CVE-2023-52620 low 2.5 2.5 FIX rhel rocky sles 2y ago Important: kernel security, bug fix, and enhancement update
CVE-2023-3817 low 2.5 FIX rocky rhel sles 2y ago RHSA-2023:7877: openssl security update (Low)
CVE-2023-3446 low 2.5 FIX rocky rhel sles 2y ago RHSA-2024:0888: edk2 security update (Low)
CVE-2023-32636 low 2.5 FIX rhel slesdebian debian 2y ago Low: mingw-glib2 security update
CVE-2023-2975 low 2.5 FIX rhel slesdebian debian 2y ago Low: openssl and openssl-fips-provider security update
CVE-2023-1729 low 2.5 FIX rhel slesdebian debian 2y ago Low: LibRaw security update
CVE-2022-48554 low 2.5 FIX rheldebian debian rocky 2y ago File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.
CVE-2023-46565 unknown FIX slesdebian debian 2y ago Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.
CVE-2024-32887 unknown FIX debian debian 2y ago Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr parameter is reflected in the response without any encoding, allowing an attac…
CVE-2024-32875 unknown FIX debian debian 2y ago Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are im…
CVE-2024-1681 unknown FIX slesdebian debian 2y ago flask-cors vulnerable to log injection when the log level is set to debug