Search

Found 14,197 results in 1041ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-9906 unknown debian debian 9mo ago Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-8671 unknown FIX debian debian sles 9mo ago A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource con…
CVE-2025-59432 unknown FIX debian debian sles 9mo ago Timing Attack Vulnerability in SCRAM Authentication
CVE-2025-41249 unknown debian debian 9mo ago Spring Framework annotation detection mechanism may result in improper authorization
CVE-2025-48041 unknown FIX debian debian sles 9mo ago Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/…
CVE-2025-48040 unknown FIX debian debian sles 9mo ago Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.e…
CVE-2025-48039 unknown FIX debian debian sles 9mo ago Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with prog…
CVE-2025-48038 unknown FIX debian debian sles 9mo ago Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with prog…
CVE-2025-57833 unknown FIX slesdebian debian 9mo ago An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with…
CVE-2025-58782 unknown debian debian 9mo ago Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
CVE-2025-57807 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing …
CVE-2025-58056 unknown FIX debian debian 9mo ago Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions
CVE-2025-58057 unknown FIX slesdebian debian 9mo ago Netty's decoders vulnerable to DoS via zip bomb style attack
CVE-2025-9784 unknown FIX debian debian 9mo ago Undertow MadeYouReset HTTP/2 DDoS Vulnerability
CVE-2025-57803 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the…
CVE-2025-55298 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in Interpr…
CVE-2025-55212 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (":") to mont…
CVE-2025-55160 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay t…
CVE-2025-55154 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/p…
CVE-2025-55004 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of …
CVE-2025-68469 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fix…
CVE-2025-53019 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multipl…
CVE-2025-53014 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` func…
CVE-2025-53101 unknown FIX debian debian sles 9mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multip…
CVE-2025-54988 unknown FIX debian debian 10mo ago Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
CVE-2025-5115 unknown FIX debian debian sles 10mo ago Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
CVE-2025-41242 unknown debian debian 10mo ago Spring Framework MVC Applications Path Traversal Vulnerability
CVE-2025-55163 unknown FIX slesdebian debian 10mo ago Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
CVE-2025-8747 unknown FIX debian debian 10mo ago Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-8885 unknown FIX debian debian sles 10mo ago Bouncy Castle for Java on All (API modules) allows Excessive Allocation
CVE-2025-55159 unknown FIX slesdebian debian 10mo ago slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing …
CVE-2025-54368 unknown FIX slesdebian debian 10mo ago uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the a…
CVE-2025-54799 unknown FIX debian debian 10mo ago Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforc…
CVE-2025-54410 unknown debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulne…
CVE-2025-54388 unknown FIX debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.…
CVE-2025-53015 unknown FIX debian debian sles 11mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion co…
CVE-2025-54121 unknown FIX slesdebian debian 11mo ago Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part …
CVE-2025-7962 unknown debian debian sles 11mo ago Jakarta Mail vulnerable to SMTP Injection
CVE-2025-50151 unknown debian debian 11mo ago Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
CVE-2025-49656 unknown debian debian 11mo ago Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
CVE-2025-53643 unknown FIX slesdebian debian 11mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trail…
CVE-2025-53689 unknown FIX debian debian 11mo ago Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
CVE-2025-48924 unknown FIX debian debian sles 11mo ago Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.…
CVE-2025-6554 unknown 1.5 KEVFIX debian debian 11mo ago Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web bro…
CVE-2025-53103 unknown FIX debian debian sles 11mo ago junit-platform-reporting can leak Git credentials through its OpenTestReportGeneratingListener
CVE-2025-52890 unknown FIX debian debian 11mo ago Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security optio…
CVE-2025-52889 unknown FIX debian debian 11mo ago Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) th…
CVE-2022-49957 unknown FIX slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: kcm: fix strp_init() order and cleanup strp_init() is called just a few lines above this csk->sk_user_data check, it also initial…
CVE-2025-49124 unknown FIX slesdebian debian 1y ago Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects A…
CVE-2025-41234 unknown FIX debian debian 1y ago Spring Framework vulnerable to a reflected file download (RFD)
CVE-2025-49146 unknown FIX debian debian sles 1y ago pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
CVE-2025-32433 unknown 2.5 KEVEXPFIX debian debian sles 1y ago Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially l…
CVE-2024-42009 unknown 1.5 KEVFIX debian debian 1y ago RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desan…
CVE-2025-49128 unknown FIX debian debian 1y ago Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
CVE-2025-5419 unknown 1.5 KEVFIX debian debian 1y ago Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could a…
CVE-2025-35036 unknown debian debian 1y ago Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
CVE-2025-4949 unknown debian debian sles 1y ago Eclipse JGit XML External Entity (XXE) Vulnerability
CVE-2025-22233 unknown debian debian 1y ago Spring Framework DataBinder Case Sensitive Match Exception
CVE-2025-47279 unknown FIX debian debian 1y ago Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server …
CVE-2025-46392 unknown FIX debian debian 1y ago Apache Commons Configuration Uncontrolled Resource Consumption
CVE-2025-1948 unknown FIX debian debian 1y ago Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit
CVE-2024-13009 unknown FIX slesdebian debian 1y ago **UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
CVE-2025-27533 unknown 1.0 EXPFIX debian debian 1y ago Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
CVE-2025-27820 unknown FIX debian debian sles 1y ago Apache HttpClient disables domain checks
CVE-2025-32434 unknown FIX debian debian 1y ago PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command …
CVE-2025-3730 unknown FIX debian debian 1y ago A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation …
CVE-2025-22872 unknown FIX debian debian sles 1y ago The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly…
CVE-2025-30215 unknown FIX debian debian 1y ago NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.27 and 2.11.1, the management of JetStream assets h…
CVE-2025-3573 unknown FIX debian debian 1y ago Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This v…
CVE-2025-31672 unknown debian debian 1y ago Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
CVE-2025-29480 unknown debian debian sles 1y ago Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invali…
CVE-2025-3136 unknown debian debian 1y ago A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAlloc…
CVE-2025-3121 unknown debian debian 1y ago A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is …
CVE-2025-27556 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.L…
CVE-2025-3001 unknown FIX debian debian 1y ago A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approac…
CVE-2025-3000 unknown debian debian 1y ago A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on…
CVE-2025-2999 unknown FIX debian debian 1y ago A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Atta…
CVE-2025-2998 unknown FIX debian debian 1y ago A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory c…
CVE-2025-2953 unknown debian debian 1y ago A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of servic…
CVE-2025-2783 unknown 2.5 KEVEXPFIX debian debian 1y ago Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability…
CVE-2025-30474 unknown FIX debian debian sles 1y ago Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-27553 unknown FIX debian debian sles 1y ago Apache Commons VFS Has Relative Path Traversal Vulnerability
CVE-2020-36843 unknown FIX slesdebian debian 1y ago Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check
CVE-2025-2149 unknown debian debian 1y ago A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of t…
CVE-2025-2148 unknown debian debian 1y ago A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component T…
CVE-2025-26699 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-ser…
CVE-2025-4432 unknown FIX debian debian 1y ago Ring: some aes functions may panic when overflow checking is enabled in ring in github.com/briansmith/ring
CVE-2025-1940 unknown FIX debian debian 1y ago A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue onl…
CVE-2025-26791 unknown FIX slesdebian debian 1y ago DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
CVE-2025-25193 unknown FIX slesdebian debian 1y ago Denial of Service attack on windows app using Netty
CVE-2025-25188 unknown FIX debian debian 1y ago Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DN…
CVE-2025-24970 unknown FIX slesdebian debian 1y ago SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
CVE-2024-57699 unknown FIX debian debian 1y ago Netplex Json-smart Uncontrolled Recursion vulnerability
CVE-2025-0411 unknown 1.5 KEVFIX debian debian sles 1y ago 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2025-24374 unknown FIX debian debian 1y ago Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
CVE-2025-24814 unknown FIX debian debian 1y ago Apache Solr vulnerable to Execution with Unnecessary Privileges
CVE-2024-52012 unknown FIX debian debian 1y ago Apache Solr Relative Path Traversal vulnerability
CVE-2024-5138 unknown FIX debian debian 1y ago The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse …
CVE-2023-0482 unknown debian debian 1y ago Insecure Temporary File in RESTEasy
CVE-2024-56374 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a p…