Vulnerability index

Browse CVEs

37 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2026-24061 KEVEPSS 98%

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Fix: after 2.7
Fix from $2,300 2026-01-21
Debian Linux HIGH 8.8
CVE-2025-49113 KEVEPSS 98%

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n…

Fix: 1.5.10 / 1.6.11+
Fix from $1,950 2025-06-02
Debian Linux HIGH 8.1
CVE-2025-27363 KEVEPSS 28%

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font sub…

Fix: after 2.13.0
Fix from $1,950 2025-03-11
Debian Linux HIGH 7.1
CVE-2024-53150 KEV

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current…

Fix: 5.4.287 / 5.10.231+
Fix from $1,950 2024-12-24
Debian Linux HIGH 7.8
CVE-2024-53104 KEV

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_forma…

Fix: 4.19.324 / 5.4.286+
Fix from $1,950 2024-12-02
Debian Linux HIGH 8.8
CVE-2024-44308 KEVEPSS 9%

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS…

Fix: 2.1.1 / 15.1.1+
Fix from $1,950 2024-11-20
Debian Linux MEDIUM 6.3
CVE-2024-44309 KEVEPSS 23%

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.…

Fix: 2.1.1 / 15.1.1+
Fix from $1,600 2024-11-20
Debian Linux MEDIUM 5.5
CVE-2024-50302 KEV

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by…

Fix: 3.2 / 4.19.324+
Fix from $1,600 2024-11-19
Debian Linux HIGH 7.8
CVE-2024-36971 KEV

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce …

Fix: 4.19.316 / 5.4.278+
Fix from $1,950 2024-06-10
Debian Linux MEDIUM 6.1
CVE-2024-37383 KEVEPSS 73%

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Fix: 1.5.7 / 1.6.7+
Fix from $1,600 2024-06-07
Debian Linux HIGH 7.8
CVE-2023-7101 KEVEPSS 17%

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut…

Fix: after 0.65
Fix from $1,950 2023-12-24
Debian Linux MEDIUM 5.4
CVE-2023-5631 KEVEPSS 76%

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because …

Fix: 1.4.15 / 1.5.5+
Fix from $1,600 2023-10-18
Debian Linux MEDIUM 6.1
CVE-2023-43770 KEVEPSS 58%

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/l…

Fix: 1.4.14 / 1.5.4+
Fix from $1,600 2023-09-22
Debian Linux HIGH 7.8
CVE-2023-0386 KEVEPSS 8%

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s…

Fix: 5.15.91 / 6.1.9+
Fix from $1,950 2023-03-22
Debian Linux HIGH 7.0
CVE-2023-0266 KEV

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be u…

Fix: 4.14.303 / 4.19.270+
Fix from $1,950 2023-01-30
Debian Linux HIGH 7.5
CVE-2022-30333 KEVEPSS 99%

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by …

Fix: 6.12+
Fix from $1,950 2022-05-09
Debian Linux HIGH 7.8
CVE-2021-3560 KEVEPSS 22%

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r…

Fix: 0.119+
Fix from $1,950 2022-02-16
Debian Linux HIGH 8.5
CVE-2021-39144 KEVEPSS 98%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 7.8
CVE-2021-22204 KEVEPSS 100%

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malici…

Fix: 12.24+
Fix from $1,950 2021-04-23
Debian Linux CRITICAL 9.8
CVE-2021-1871 KEVEPSS 7%

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update…

Fix: 10.15.7 / 11.2+
Fix from $2,300 2021-04-02
Debian Linux HIGH 7.2
CVE-2021-21311 KEVEPSS 90%

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request for…

Fix: 4.7.9+
Fix from $1,950 2021-02-11
Debian Linux CRITICAL 9.8
CVE-2020-16846 KEVEPSS 100%

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Debian Linux MEDIUM 6.1
CVE-2020-13965 KEVEPSS 77%

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am…

Fix: 1.3.12 / 1.4.5+
Fix from $1,600 2020-06-09
Debian Linux CRITICAL 9.8
CVE-2020-11651 KEVEPSS 97%

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate…

Fix: 2019.2.4 / 3000.2+
Fix from $2,300 2020-04-30
Debian Linux MEDIUM 6.5
CVE-2020-11652 KEVEPSS 86%

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some meth…

Fix: 2019.2.4 / 3000.2+
Fix from $1,600 2020-04-30
Debian Linux CRITICAL 9.8
CVE-2020-7247 KEVEPSS 99%

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as…

Patch available
Fix from $2,300 2020-01-29
Debian Linux HIGH 7.8
CVE-2019-2215 KEVEPSS 44%

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit thi…

Patch available
Fix from $1,950 2019-10-11
Debian Linux HIGH 7.5
CVE-2016-9079 KEVEPSS 87%

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting…

Fix: 45.5.1 / 50.0.2+
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-6789 KEVEPSS 82%

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may h…

Fix: 4.90.1+
Fix from $2,300 2018-02-08
Debian Linux HIGH 7.8
CVE-2017-16651 KEVEPSS 37%

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, i…

Fix: after 1.1.9
Fix from $1,950 2017-11-09