Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 10.0
CVE-2024-42472
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app us…
Debian Linux
1.14.10 / 1.15.10+
HIGH 8.8
CVE-2023-43655
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed …
Debian Linux
1.10.27 / 2.2.21+
HIGH 7.8
CVE-2023-27635
debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is…
Debmany
Mitigation only
HIGH 8.8
CVE-2022-31086
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…
Debian Linux
8.0+
HIGH 7.8
CVE-2022-31087
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…
Debian Linux
8.0+
MEDIUM 5.3
CVE-2022-31088
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…
Debian Linux
8.0+
HIGH 8.8
CVE-2021-29454
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.…
Debian Linux
3.1.42 / 4.0.2+
HIGH 7.5
CVE-2021-32558EPSS 9%
An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Aster…
Debian Linux
13.38.3 / 16.19.1+
MEDIUM 5.9
CVE-2019-25031
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HT…
Debian Linux
1.9.5+
MEDIUM 5.3
CVE-2020-36308
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading ti…
Debian Linux
4.0.7 / 4.1.1+
MEDIUM 5.3
CVE-2021-28963
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
Debian Linux
3.2.1+
HIGH 8.2
CVE-2021-21381
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before versi…
Debian Linux
1.10.2+
HIGH 8.8
CVE-2021-21261
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` ser…
Debian Linux
1.8.5 / 1.10.0+
HIGH 7.0
CVE-2020-15238
Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argume…
Debian Linux
2.1.4+
CRITICAL 9.8
CVE-2020-15227EPSS 35%
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters…
Debian Linux
2.0.19 / 2.1.13+
MEDIUM 5.9
CVE-2020-14928
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds…
Debian Linux
after 3.36.3
MEDIUM 5.9
CVE-2020-14954
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS"…
Debian Linux
1.14.4 / 20200619+
MEDIUM 6.5
CVE-2020-12108
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
Debian Linux
2.1.31+
MEDIUM 6.1
CVE-2019-18860EPSS 6%
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
Debian Linux
4.9+
CRITICAL 9.8
CVE-2014-4172EPSS 6%
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.…
Debian Linux
1.0.2 / 1.3.3+
HIGH 7.8
CVE-2010-4654
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
Debian Linux
0.16.3+
HIGH 7.5
CVE-2019-8322
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. T…
Debian Linux
after 3.0.2
HIGH 7.5
CVE-2019-8323
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is…
Debian Linux
after 3.0.2
HIGH 7.5
CVE-2019-8325
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence in…
Debian Linux
after 3.0.2
HIGH 8.8
CVE-2017-18266
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER enviro…
Debian Linux
1.1.3+
CRITICAL 9.8
CVE-2017-0372EPSS 12%
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
Debian Linux
after 1.23.15
HIGH 7.5
CVE-2018-6519
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for…
Debian Linux
1.10.4 / 2.3.5+
HIGH 8.8
CVE-2017-17511
KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attac…
Debian Linux
Mitigation only
HIGH 8.8
CVE-2017-17514
boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote …
Debian Linux
Mitigation only
HIGH 8.8
CVE-2017-17515
etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might all…
Debian Linux
Mitigation only