Search

Found 28,572 results in 3819ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-52971 medium 5.5 FIX rocky rhel sles 5mo ago MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.
CVE-2026-21892 unknown FIX debian debian 5mo ago Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsaf…
CVE-2025-32365 medium 5.5 FIX rocky rhel sles 5mo ago Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
CVE-2025-69230 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is…
CVE-2025-69229 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a …
CVE-2025-69228 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontro…
CVE-2025-69227 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS a…
CVE-2025-69226 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path no…
CVE-2025-69225 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There…
CVE-2025-69224 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII…
CVE-2025-69223 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be a…
CVE-2026-21452 unknown debian debian 5mo ago MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation
CVE-2025-68131 unknown FIX debian debian sles 5mo ago CBORDecoder reuse can leak shareable values across decode calls
CVE-2025-68950 unknown FIX debian debian sles 5mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a …
CVE-2025-68618 unknown FIX debian debian sles 5mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7…
CVE-2025-67746 unknown FIX debian debian sles 5mo ago Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI cont…
CVE-2023-54164 unknown FIX slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix iso_conn related locking and validity issues sk->sk_state indicates whether iso_pi(sk)->conn is valid. Operat…
CVE-2026-0810 unknown debian debian 5mo ago A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `T…
CVE-2023-54130 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: avoid WARN_ON() for sanity check, use proper error handling Commit 55d1cbbbb29e ("hfs/hfsplus: use WARN_ON for sanit…
CVE-2025-68351 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel vulnerabilities
CVE-2025-68480 unknown slesdebian debianubuntu ubuntu 6mo ago Python marshmallow vulnerabilities
CVE-2025-14957 medium 5.5 5.5 debian debian webassembly 6mo ago A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/wasm/wasm-ir-builde…
CVE-2025-68161 unknown FIX debian debian sles 6mo ago Apache Log4j does not verify the TLS hostname in its Socket Appender
CVE-2025-68463 medium 4.9 4.9 FIX debian debian 6mo ago Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
CVE-2025-14841 low 3.3 3.3 FIX debian debian 6mo ago A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in t…
CVE-2025-8291 medium 5.5 FIX rocky rhelalmalinux almalinux 6mo ago The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD re…
CVE-2025-6491 medium 5.5 FIX rockyalmalinux almalinux rhel 6mo ago In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null …
CVE-2025-5987 medium 5.5 FIX rheldebian debian sles 6mo ago Moderate: libssh security update
CVE-2025-1735 medium 5.5 FIX rockyalmalinux almalinux rhel 6mo ago In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This coul…
CVE-2025-1220 medium 5.5 FIX rocky rhelalmalinux almalinux 6mo ago In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null cha…
CVE-2024-29371 unknown FIX slesdebian debian 6mo ago jose4j is vulnerable to DoS via compressed JWE content
CVE-2025-61985 medium 5.5 FIX rocky rhel sles 6mo ago ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
CVE-2025-61984 medium 5.5 FIX rocky rhel sles 6mo ago ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrus…
CVE-2025-38499 medium 5.5 5.5 FIX rhel sles rocky 6mo ago Important: kernel security update
CVE-2025-68154 unknown FIX debian debian 6mo ago systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows syste…
CVE-2025-68146 unknown FIX slesdebian debian 6mo ago filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user …
CVE-2025-68142 unknown FIX debian debian 6mo ago PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption extension (`pymdownx.blocks.caption`).…
CVE-2023-53900 medium 6.1 6.1 debian debian spip 6mo ago Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo …
CVE-2025-68315 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68307 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68251 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loops due to corrupted subpage compact indexes Robert reported an infinite loop observed by two crafted ima…
CVE-2025-68239 unknown FIX slesdebian debian google 6mo ago In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access before closing files opened by open_exec() bm_register_write() opens an executable file using o…
CVE-2025-68201 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-40347 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-67735 unknown FIX slesdebian debian 6mo ago Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder
CVE-2025-65431 unknown FIX debian debian 6mo ago django-allauth's Okta and NetIQ implementations used a mutable identifier for authorization decisions
CVE-2025-65430 unknown FIX debian debian 6mo ago django-allauth does not reject access tokens for inactive users
CVE-2025-14569 medium 5.3 5.3 debian debian 6mo ago A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /whisper.cpp/examples/common-whisper.cpp. The manipulation results in use after …
CVE-2025-40345 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-14512 medium 6.5 6.5 FIX rheldebian debian sles gnomeredhat 6mo ago A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when pro…
CVE-2025-53069 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53062 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53054 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53053 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53045 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53044 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53042 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53040 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-67713 unknown FIX debian debian 6mo ago Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishing flows after login. Protocol-relative URLs like /…
CVE-2025-66628 unknown FIX debian debian sles 6mo ago ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in…
CVE-2025-14087 medium 5.6 5.6 FIX rheldebian debian sles gnome 6mo ago A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GV…
CVE-2025-14307 unknown debian debianubuntu ubuntu 6mo ago Robocode vulnerabilities
CVE-2025-14306 unknown debian debianubuntu ubuntu 6mo ago Robocode vulnerabilities
CVE-2025-6218 unknown 1.5 KEVFIX debian debian 6mo ago RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-39979 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-39925 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-40281 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-40280 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-40278 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-66564 unknown FIX debian debian 6mo ago Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (whi…
CVE-2025-66506 unknown FIX debian debian 6mo ago Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a call to str…
CVE-2025-66516 unknown FIX debian debianubuntu ubuntu 6mo ago Apache Tika vulnerabilities
CVE-2025-40264 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-40263 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-40262 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-40261 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-40257 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-40254 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-40250 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-40214 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of …
CVE-2025-14010 medium 5.5 5.5 FIX debian debian redhat 6mo ago Ansible Community General Collection is vulnerable to exposure of sensitive information
CVE-2024-3884 unknown debian debian 6mo ago Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded
CVE-2025-66453 unknown slesdebian debian 6mo ago Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
CVE-2025-65955 unknown FIX debian debian sles 6mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests …
CVE-2025-4598 medium 4.7 4.7 FIX arch arch rhel sles systemd_projectredhat 6mo ago Moderate: systemd security update
CVE-2025-61727 unknown FIX debian debian sles 6mo ago An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com doe…
CVE-2025-64460 unknown FIX slesdebian debian 6mo ago Django is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372 unknown FIX slesdebian debian 6mo ago Django is vulnerable to SQL injection in column aliases
CVE-2025-66412 medium 5.4 5.4 FIX debian debian angular 6mo ago Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scriptin…
CVE-2025-9714 medium 5.5 5.5 FIX rheldebian debian sles xmlsoft 6mo ago Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPat…
CVE-2025-40186 medium 5.5 FIX slesdebian debian rhel 6mo ago In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). syzbot reported the splat below in tcp_conn_request(). [0] If a l…
CVE-2025-40185 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-40058 medium 5.5 FIX rhel sles rocky 6mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-39981 medium 5.5 FIX rhel sles rocky 6mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-39955 medium 5.5 FIX rocky rhel sles 6mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-39918 medium 5.5 FIX rhel sles rocky 6mo ago Moderate: kernel security update
CVE-2025-12183 unknown debian debian 6mo ago LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
CVE-2025-66382 low 2.9 2.9 debian debian sles libexpat_project 6mo ago In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2025-66035 unknown FIX debian debian 6mo ago Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF tok…
CVE-2025-9624 unknown debian debian 6mo ago OpenSearch is vulnerable to DoS via complex query_string inputs