Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2025-62799

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.…

Fix: 2.6.11 / 3.3.1+
Fix from $2,300 2026-02-03
Debian Linux CRITICAL 9.8
CVE-2025-68670

xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from im…

Fix: 0.10.5+
Fix from $2,300 2026-01-27
Debian Linux CRITICAL 9.8
CVE-2026-24061 KEVEPSS 98%

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Fix: after 2.7
Fix from $2,300 2026-01-21
Debian Linux CRITICAL 9.8
CVE-2025-68615EPSS 43%

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd …

Fix: 5.9.5+
Fix from $2,300 2025-12-23
Devscripts CRITICAL 9.8
CVE-2025-8454

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to …

Mitigation only
Fix from $2,300 2025-08-01
Yubiserver CRITICAL 9.8
CVE-2015-0842

yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.

Mitigation only
Fix from $2,300 2025-06-26
Yubiserver CRITICAL 9.8
CVE-2015-0843

yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.

Mitigation only
Fix from $2,300 2025-06-26
Pdns CRITICAL 9.8
CVE-2014-7210

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of p…

Fix: 3.3.1-1+
Fix from $2,300 2025-06-26
Debian Linux CRITICAL 9.8
CVE-2025-2291

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to l…

Fix: 1.24.1+
Fix from $2,300 2025-04-16
Debian Linux CRITICAL 9.8
CVE-2025-0838

There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,ma…

Fix: 20250127.0+
Fix from $2,300 2025-02-21
Debian Linux CRITICAL 9.9
CVE-2025-0781

An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating…

Fix: after 2020.3.19
Fix from $2,300 2025-01-28
Debian Linux CRITICAL 9.8
CVE-2024-47606

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_the…

Fix: 1.24.10+
Fix from $2,300 2024-12-12
Debian Linux CRITICAL 9.8
CVE-2024-49369

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor…

Fix: 2.11.12 / 2.12.11+
Fix from $2,300 2024-11-12
Debian Linux CRITICAL 9.8
CVE-2024-52533

gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient f…

Fix: 2.82.1+
Fix from $2,300 2024-11-11
Debian Linux CRITICAL 9.1
CVE-2024-47685

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that …

Fix: 4.19.323 / 5.4.285+
Fix from $2,300 2024-10-21
Debian Linux CRITICAL 9.8
CVE-2024-47175EPSS 64%

CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFrom…

Fix: after 2.0.0
Fix from $2,300 2024-09-26
Debian Linux CRITICAL 10.0
CVE-2024-42472

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app us…

Fix: 1.14.10 / 1.15.10+
Fix from $2,300 2024-08-15
Debian Linux CRITICAL 9.1
CVE-2024-37371

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens wi…

Fix: 1.21.3+
Fix from $2,300 2024-06-28
Debian Linux CRITICAL 9.1
CVE-2024-5197

There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter…

Fix: 1.14.1+
Fix from $2,300 2024-06-03
Debian Linux CRITICAL 9.3
CVE-2024-36913

In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it i…

Fix: 6.1.143 / 6.6.31+
Fix from $2,300 2024-05-30
Debian Linux CRITICAL 9.8
CVE-2024-25714

In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the compa…

Fix: after 1.1.3
Fix from $2,300 2024-02-11
Debian Linux CRITICAL 9.8
CVE-2024-25189

libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side cha…

No fix yet
Fix from $2,300 2024-02-08
Debian Linux CRITICAL 9.8
CVE-2024-0808

Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious f…

Fix: 121.0.6167.85+
Fix from $2,300 2024-01-24
Debian Linux CRITICAL 9.8
CVE-2023-51714

An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2…

Fix: 5.15.17 / 6.2.11+
Fix from $2,300 2023-12-24
Debian Linux CRITICAL 9.8
CVE-2023-42464

A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, …

Fix: 3.1.17+
Fix from $2,300 2023-09-20
Debian Linux CRITICAL 9.8
CVE-2019-19450

paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar…

Fix: 3.5.31+
Fix from $2,300 2023-09-20
Debian Linux CRITICAL 9.8
CVE-2023-40186

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Integer…

Fix: 2.11.0+
Fix from $2,300 2023-08-31
Debian Linux CRITICAL 9.8
CVE-2023-40567

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-…

Fix: 2.11.0+
Fix from $2,300 2023-08-31
Debian Linux CRITICAL 9.8
CVE-2023-40569

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-…

Fix: 2.11.0+
Fix from $2,300 2023-08-31
Debian Linux CRITICAL 9.1
CVE-2023-40188

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-…

Fix: 2.11.0+
Fix from $2,300 2023-08-31