Search

Found 4,677 results in 587ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-7425 high 7.8 7.8 FIX rheldebian debian sles 10mo ago A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragm…
CVE-2025-52999 high 8.0 FIX rhel rockydebian debian 10mo ago RHSA-2025:14126: pki-deps:10.6 security update (Important)
CVE-2025-6965 high 9.0 EXPFIX rhel rocky sles 10mo ago RHSA-2025:14101: mingw-sqlite security update (Important)
CVE-2025-5994 high 8.0 FIX rhel sles rocky 10mo ago RHSA-2025:11884: unbound security update (Important)
CVE-2025-27151 high 8.0 FIX rhel sles rocky 10mo ago Important: redis:7 security update
CVE-2025-8035 high 8.0 FIX almalinux almalinux rhel rocky 11mo ago Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corru…
CVE-2025-8034 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evid…
CVE-2025-8033 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefo…
CVE-2025-8032 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thun…
CVE-2025-8031 high 8.0 FIX almalinux almalinux rhel rocky 11mo ago The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 12…
CVE-2025-8030 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox …
CVE-2025-8029 high 8.0 FIX almalinux almalinux rhel rocky 11mo ago Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13…
CVE-2025-8028 high 8.0 FIX rhel rockydebian debian 11mo ago On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulne…
CVE-2025-8027 high 8.0 FIX rhel rockydebian debian 11mo ago On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability was fixed in Firefox 141, Firefo…
CVE-2025-48385 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-48384 high 9.5 KEVFIX rhel rockydebian debian 11mo ago Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.
CVE-2025-48367 high 8.0 FIX rhel rocky sles 11mo ago RHSA-2025:12006: redis:6 security update (Important)
CVE-2025-46835 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-38425 high 8.0 FIX rhel slesdebian debian 11mo ago In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: check msg length in SMBUS block read For SMBUS block read, do not continue to read if the message length passed from …
CVE-2025-38089 high 8.0 FIX rhel slesdebian debian 11mo ago Important: kernel security update
CVE-2025-32023 high 9.0 EXPFIX rhel rocky sles 11mo ago RHSA-2025:12006: redis:6 security update (Important)
CVE-2025-27614 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-27613 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2024-58002 high 8.0 FIX rhel rocky sles 11mo ago Important: kernel security update
CVE-2024-52006 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2024-50349 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-50106 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-30761 high 8.0 FIX rhelalmalinux almalinux rocky 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-30754 high 8.0 FIX rhel rocky sles 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-30749 high 8.0 FIX rhel rocky sles 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-31650 high 9.0 EXPFIX arch arch rhel rocky 11mo ago Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory …
CVE-2024-56337 high 8.0 FIX rhel rocky sles 11mo ago Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 throu…
CVE-2025-50059 high 8.0 FIX rhel rocky sles 11mo ago RHSA-2025:10873: java-21-openjdk security update (Important)
CVE-2024-6174 high 8.0 FIX rheldebian debian sles 11mo ago RHSA-2025:11324: cloud-init security update (Important)
CVE-2025-7424 high 7.5 7.5 FIX debian debian sles rhel xmlsoftredhat 11mo ago A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allow…
CVE-2025-6021 high 7.5 7.5 FIX rhelarch arch rocky xmlsoftredhat 11mo ago RHSA-2025:10698: libxml2 security update (Important)
CVE-2025-6032 high 8.0 FIX rhel rockydebian debian 11mo ago RHSA-2025:10551: container-tools:rhel8 security update (Important)
CVE-2025-37799 high 8.0 FIX rhel slesdebian debian 11mo ago Important: kernel security update
CVE-2025-22004 high 8.0 FIX rhel rocky sles 11mo ago Important: kernel security update
CVE-2025-21887 high 8.0 FIX rhel slesdebian debian 11mo ago Important: kernel security update
CVE-2025-21759 high 8.0 FIX rhel rocky sles 11mo ago Important: kernel security update
CVE-2022-49846 high 8.0 FIX rhel slesdebian debian 11mo ago Important: kernel security update
CVE-2025-5372 high 8.8 8.8 FIX rockydebian debian sles libsshredhat 11mo ago RHSA-2025:21977: libssh security update (Moderate)
CVE-2025-5986 high 8.0 FIX rhel rocky sles 11mo ago RHSA-2025:10246: thunderbird security update (Important)
CVE-2025-6430 high 8.0 FIX rhel rockydebian debian 11mo ago When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a we…
CVE-2025-6429 high 8.0 FIX rhel rockydebian debian 11mo ago Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restric…
CVE-2025-6425 high 8.0 FIX rhel rockydebian debian 11mo ago An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode,…
CVE-2025-6424 high 8.0 FIX rhel rockydebian debian 11mo ago A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.…
CVE-2025-4517 high 8.0 FIX rocky rheldebian debian 11mo ago Important: python3.9 security update
CVE-2025-4435 high 8.0 FIX rocky rheldebian debian 11mo ago Important: python3.9 security update
CVE-2025-4330 high 8.0 FIX rocky rheldebian debian 11mo ago Important: python3.9 security update
CVE-2025-4138 high 8.0 FIX rocky rheldebian debian 11mo ago Important: python3.9 security update
CVE-2024-12718 high 8.0 FIX rhel rocky sles 11mo ago Important: python3.9 security update
CVE-2025-32462 high 9.0 EXPFIX rhel rocky sles 11mo ago Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
CVE-2024-28956 high 8.0 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2011-10007 high 8.0 FIX sles rhel rocky 1y ago RHSA-2025:9605: perl-File-Find-Rule security update (Important)
CVE-2025-6019 high 8.0 FIX rhelarch arch rocky 1y ago RHSA-2025:9878: libblockdev security update (Important)
CVE-2025-49180 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. This issue leads to an integer overflow when computing the total size to allocat…
CVE-2025-49179 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length …
CVE-2025-49178 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial…
CVE-2025-49177 high 8.0 FIX rhel slesdebian debian 1y ago A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
CVE-2025-49176 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size …
CVE-2025-49175 high 8.0 FIX rhel rocky sles 1y ago A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potenti…
CVE-2025-40908 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:9329: perl-YAML-LibYAML security update (Important)
CVE-2025-5473 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:9165: gimp:2.8 security update (Important)
CVE-2025-48798 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:9165: gimp:2.8 security update (Important)
CVE-2025-48797 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:9165: gimp:2.8 security update (Important)
CVE-2025-4404 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:9188: idm:DL1 security update (Important)
CVE-2025-48734 high 8.0 FIX rheldebian debian sles 1y ago Important: apache-commons-beanutils security update
CVE-2025-37750 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-22126 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21999 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21979 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21969 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21963 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21961 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-47947 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:8844: mod_security security update (Important)
CVE-2025-30399 high 8.0 rhel rocky 1y ago RHSA-2025:8815: .NET 9.0 security update (Important)
CVE-2025-40907 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:8696: perl-FCGI:0.78 security update (Important)
CVE-2025-37943 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-37785 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-22055 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21997 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21926 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-21920 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2025-4447 high 8.0 sles rhel 1y ago RHSA-2025:8431: java-1.8.0-ibm security update (Important)
CVE-2025-23167 high 8.0 FIX rhel rockyarch arch 1y ago A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers t…
CVE-2025-23166 high 8.0 FIX rhel rockyarch arch 1y ago RHSA-2025:8514: nodejs:20 security update (Important)
CVE-2025-23165 high 8.0 FIX rhel rockyarch arch 1y ago RHSA-2025:8514: nodejs:20 security update (Important)
CVE-2025-47905 high 8.0 FIX rhel rockydebian debian 1y ago Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to d…
CVE-2025-21764 high 7.8 7.8 FIX rhel rocky sles 1y ago Moderate: kernel security update
CVE-2025-5283 high 8.0 FIX rhel rockydebian debian 1y ago Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5269 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:8756: thunderbird security update (Important)
CVE-2025-5268 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort …
CVE-2025-5267 high 8.0 FIX rhel rockydebian debian 1y ago A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunder…
CVE-2025-5266 high 8.0 FIX rhel rockydebian debian 1y ago Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thu…
CVE-2025-5264 high 8.0 FIX rhel rockydebian debian 1y ago Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's …
CVE-2025-5263 high 8.0 FIX rhel rockydebian debian 1y ago Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Fir…
CVE-2025-32910 high 8.0 FIX rocky slesdebian debian 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-32909 high 8.0 FIX rocky slesdebian debian 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)