Search

Found 18,501 results in 2016ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-49124 unknown FIX slesdebian debian 1y ago Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects A…
CVE-2025-6052 low 3.7 3.7 FIX debian debian sles gnome 1y ago A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation.…
CVE-2025-41234 unknown FIX debian debian 1y ago Spring Framework vulnerable to a reflected file download (RFD)
CVE-2025-49146 unknown FIX debian debian sles 1y ago pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
CVE-2025-5889 low 3.1 3.1 FIX slesdebian debian 1y ago A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The man…
CVE-2025-32433 unknown 2.5 KEVEXPFIX debian debian sles 1y ago Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially l…
CVE-2024-42009 unknown 1.5 KEVFIX debian debian 1y ago RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desan…
CVE-2025-49128 unknown FIX debian debian 1y ago Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
CVE-2025-48432 low 2.5 FIX arch arch slesdebian debian 1y ago An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially…
CVE-2025-5419 unknown 1.5 KEVFIX debian debian 1y ago Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-35036 unknown debian debian 1y ago Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
CVE-2025-48387 unknown FIX debian debianubuntu ubuntu 1y ago tar-fs vulnerabilities
CVE-2025-49113 critical 10.0 KEVEXPFIX arch archdebian debian 1y ago RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/…
CVE-2025-4949 unknown debian debian sles 1y ago Eclipse JGit XML External Entity (XXE) Vulnerability
CVE-2025-22233 unknown debian debian 1y ago Spring Framework DataBinder Case Sensitive Match Exception
CVE-2025-47279 unknown FIX debian debian 1y ago Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server …
CVE-2024-50044 low 3.3 3.3 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change rfcomm_sk_state_change attempts to use sock_lock so it must ne…
CVE-2024-47685 critical 9.1 9.1 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that nf_reject_ip6_tcphdr_put() was possibly sending ga…
CVE-2023-4752 low 2.5 FIX rhel sles rocky 1y ago Use After Free in GitHub repository vim/vim prior to 9.0.1858.
CVE-2022-45063 low 2.5 FIX rhel sles rocky 1y ago Low: xterm security update
CVE-2025-46392 unknown FIX debian debian 1y ago Apache Commons Configuration Uncontrolled Resource Consumption
CVE-2025-1948 unknown FIX debian debian 1y ago Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit
CVE-2024-13009 unknown FIX slesdebian debian 1y ago **UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
CVE-2025-44021 unknown FIX debian debian 1y ago OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can pro…
CVE-2025-27533 unknown 1.0 EXPFIX debian debian 1y ago Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
CVE-2025-46653 low 3.1 3.1 FIX debian debian node-formidable 1y ago Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographic…
CVE-2025-27820 unknown FIX debian debian sles 1y ago Apache HttpClient disables domain checks
CVE-2025-46394 low 3.2 3.2 FIX arch archdebian debian sles busybox 1y ago In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
CVE-2025-43973 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.
CVE-2025-43972 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.
CVE-2025-43971 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
CVE-2025-43970 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
CVE-2025-32434 unknown FIX debian debian 1y ago PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command …
CVE-2025-3730 unknown FIX debian debian 1y ago A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation …
CVE-2025-22872 unknown FIX debian debian sles 1y ago The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly…
CVE-2025-30215 unknown FIX debian debian 1y ago NATS Server may fail to authorize certain Jetstream admin APIs
CVE-2025-3573 unknown FIX debian debian 1y ago Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This v…
CVE-2025-3549 low 3.3 3.3 FIX debian debian sles assimp 1y ago A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/Ass…
CVE-2025-3548 low 3.3 3.3 FIX debian debian sles assimp 1y ago A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp up to 5.4.3. This issue affects the function aiString::Set in the library include/assimp/types.h …
CVE-2025-31672 unknown debian debian 1y ago Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
CVE-2025-29480 unknown debian debian sles 1y ago Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invali…
CVE-2025-3136 unknown debian debian 1y ago A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAlloc…
CVE-2025-31130 unknown FIX debian debian 1y ago gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxid…
CVE-2025-3121 unknown debian debian 1y ago A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is …
CVE-2025-27556 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.L…
CVE-2025-3001 unknown FIX debian debian 1y ago A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approac…
CVE-2025-3000 unknown debian debian 1y ago A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on…
CVE-2025-2999 unknown FIX debian debian 1y ago A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Atta…
CVE-2025-2998 unknown FIX debian debian 1y ago A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory c…
CVE-2025-2953 unknown debian debian 1y ago A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of servic…
CVE-2025-2923 low 3.3 3.3 debian debian sles hdfgroup 1y ago A vulnerability, which was classified as problematic, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5F_addr_encode_len of the file src/H5Fint.c. The manipulation of the…
CVE-2025-2914 low 3.3 3.3 debian debian sles hdfgroup 1y ago A vulnerability classified as problematic has been found in HDF5 up to 1.14.6. This affects the function H5FS__sinfo_Srialize_Sct_cb of the file src/H5FScache.c. The manipulation of the argument sect…
CVE-2024-12905 unknown 1.0 EXPFIX debian debianubuntu ubuntu 1y ago tar-fs vulnerabilities
CVE-2025-2783 unknown 2.5 KEVEXPFIX debian debian 1y ago Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromiu…
CVE-2025-30474 unknown FIX debian debian sles 1y ago Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-27553 unknown FIX debian debian sles 1y ago Apache Commons VFS Has Relative Path Traversal Vulnerability
CVE-2020-36843 unknown FIX slesdebian debian 1y ago Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check
CVE-2025-1550 unknown 1.0 EXPFIX debian debian 1y ago Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2025-2149 unknown debian debian 1y ago A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of t…
CVE-2025-2148 unknown debian debian 1y ago A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component T…
CVE-2025-26699 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-ser…
CVE-2025-4432 unknown FIX debian debian 1y ago Ring: some aes functions may panic when overflow checking is enabled in ring in github.com/briansmith/ring
CVE-2025-27426 unknown FIX debian debian 1y ago Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.
CVE-2025-1942 unknown FIX debian debian 1y ago When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird…
CVE-2025-1941 unknown FIX debian debian 1y ago Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firef…
CVE-2025-1940 unknown FIX debian debian 1y ago A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue onl…
CVE-2025-1376 low 2.5 2.5 debian debian sles elfutils_project 1y ago A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipu…
CVE-2025-26791 unknown FIX slesdebian debian 1y ago DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
CVE-2025-25193 unknown FIX slesdebian debian 1y ago Denial of Service attack on windows app using Netty
CVE-2025-25188 unknown FIX debian debian 1y ago Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DN…
CVE-2025-24970 unknown FIX slesdebian debian 1y ago SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
CVE-2024-57699 unknown FIX debian debian 1y ago Netplex Json-smart Uncontrolled Recursion vulnerability
CVE-2025-0411 unknown 1.5 KEVFIX debian debian sles 1y ago 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2025-24374 unknown FIX debian debian 1y ago Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
CVE-2025-24814 unknown FIX debian debian 1y ago Apache Solr vulnerable to Execution with Unnecessary Privileges
CVE-2024-52012 unknown FIX debian debian 1y ago Apache Solr Relative Path Traversal vulnerability
CVE-2025-22620 unknown FIX debian debian 1y ago gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them ap…
CVE-2024-5138 unknown FIX debian debian 1y ago The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse …
CVE-2023-0482 unknown debian debian 1y ago Insecure Temporary File in RESTEasy
CVE-2024-56374 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a p…
CVE-2024-55459 unknown debian debian 1y ago keras Path Traversal vulnerability
CVE-2024-52046 unknown FIX debian debian 2y ago Apache MINA Deserialization RCE Vulnerability
CVE-2024-56334 unknown FIX debian debian 2y ago systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` f…
CVE-2024-38819 unknown debian debian 2y ago Spring Framework Path Traversal vulnerability
CVE-2024-12801 unknown slesdebian debian 2y ago QOS.CH logback-core Server-Side Request Forgery vulnerability
CVE-2024-12798 unknown slesdebian debian google 2y ago QOS.CH logback-core Expression Language Injection vulnerability
CVE-2024-45338 unknown FIX debian debian sles 2y ago An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.
CVE-2024-54677 low 2.5 FIX slesdebian debian 2y ago Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.…
CVE-2024-7592 low 2.5 FIX rhel sles rocky 2y ago There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie…
CVE-2024-45337 unknown FIX debian debian sles 2y ago Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerCo…
CVE-2024-6156 unknown FIX debian debian 2y ago Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
CVE-2024-6219 unknown FIX debian debian 2y ago Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
CVE-2024-55601 unknown FIX debian debian 2y ago Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks…
CVE-2024-55565 unknown FIX debian debian 2y ago nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
CVE-2024-53908 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subje…
CVE-2024-53907 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack…
CVE-2024-38829 unknown debian debian 2y ago Spring LDAP data exposure vulnerability
CVE-2024-37303 unknown FIX debian debian 2y ago Synapse's unauthenticated writes to the media repository allow planting of problematic content
CVE-2024-37302 unknown FIX debian debian 2y ago Synapse denial of service through media disk space consumption
CVE-2024-53981 unknown FIX slesdebian debian 2y ago python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of the first boundary and any tailing bytes after the…