Vulnerability index

Browse CVEs

37 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-24061 KEVEPSS 98% telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. Debian Linux after 2.7 Fix from $2,3002026-01-21 HIGH 8.8 CVE-2025-49113 KEVEPSS 98% Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n… Debian Linux 1.5.10 / 1.6.11+ Fix from $1,9502025-06-02 HIGH 8.1 CVE-2025-27363 KEVEPSS 28% An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font sub… Debian Linux after 2.13.0 Fix from $1,9502025-03-11 HIGH 7.1 CVE-2024-53150 KEV In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current… Debian Linux 5.4.287 / 5.10.231+ Fix from $1,9502024-12-24 HIGH 7.8 CVE-2024-53104 KEV In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_forma… Debian Linux 4.19.324 / 5.4.286+ Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-44308 KEVEPSS 9% The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS… Debian Linux 2.1.1 / 15.1.1+ Fix from $1,9502024-11-20 MEDIUM 6.3 CVE-2024-44309 KEVEPSS 23% A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.… Debian Linux 2.1.1 / 15.1.1+ Fix from $1,6002024-11-20 MEDIUM 5.5 CVE-2024-50302 KEV In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by… Debian Linux 3.2 / 4.19.324+ Fix from $1,6002024-11-19 HIGH 7.8 CVE-2024-36971 KEV In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce … Debian Linux 4.19.316 / 5.4.278+ Fix from $1,9502024-06-10 MEDIUM 6.1 CVE-2024-37383 KEVEPSS 73% Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. Debian Linux 1.5.7 / 1.6.7+ Fix from $1,6002024-06-07 HIGH 7.8 CVE-2023-7101 KEVEPSS 17% Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut… Debian Linux after 0.65 Fix from $1,9502023-12-24 MEDIUM 5.4 CVE-2023-5631 KEVEPSS 76% Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because … Debian Linux 1.4.15 / 1.5.5+ Fix from $1,6002023-10-18 MEDIUM 6.1 CVE-2023-43770 KEVEPSS 58% Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/l… Debian Linux 1.4.14 / 1.5.4+ Fix from $1,6002023-09-22 HIGH 7.8 CVE-2023-0386 KEVEPSS 8% A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s… Debian Linux 5.15.91 / 6.1.9+ Fix from $1,9502023-03-22 HIGH 7.0 CVE-2023-0266 KEV A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be u… Debian Linux 4.14.303 / 4.19.270+ Fix from $1,9502023-01-30 HIGH 7.5 CVE-2022-30333 KEVEPSS 99% RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by … Debian Linux 6.12+ Fix from $1,9502022-05-09 HIGH 7.8 CVE-2021-3560 KEVEPSS 22% It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r… Debian Linux 0.119+ Fix from $1,9502022-02-16 HIGH 8.5 CVE-2021-39144 KEVEPSS 98% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 7.8 CVE-2021-22204 KEVEPSS 100% Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malici… Debian Linux 12.24+ Fix from $1,9502021-04-23 CRITICAL 9.8 CVE-2021-1871 KEVEPSS 7% A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update… Debian Linux 10.15.7 / 11.2+ Fix from $2,3002021-04-02 HIGH 7.2 CVE-2021-21311 KEVEPSS 90% Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request for… Debian Linux 4.7.9+ Fix from $1,9502021-02-11 CRITICAL 9.8 CVE-2020-16846 KEVEPSS 100% An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel… Debian Linux 2015.8.10 / 2015.8.13+ Fix from $2,3002020-11-06 MEDIUM 6.1 CVE-2020-13965 KEVEPSS 77% An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am… Debian Linux 1.3.12 / 1.4.5+ Fix from $1,6002020-06-09 CRITICAL 9.8 CVE-2020-11651 KEVEPSS 97% An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate… Debian Linux 2019.2.4 / 3000.2+ Fix from $2,3002020-04-30 MEDIUM 6.5 CVE-2020-11652 KEVEPSS 86% An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some meth… Debian Linux 2019.2.4 / 3000.2+ Fix from $1,6002020-04-30 CRITICAL 9.8 CVE-2020-7247 KEVEPSS 99% smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as… Debian Linux Patch available Fix from $2,3002020-01-29 HIGH 7.8 CVE-2019-2215 KEVEPSS 44% A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit thi… Debian Linux Patch available Fix from $1,9502019-10-11 HIGH 7.5 CVE-2016-9079 KEVEPSS 87% A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting… Debian Linux 45.5.1 / 50.0.2+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2018-6789 KEVEPSS 82% An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may h… Debian Linux 4.90.1+ Fix from $2,3002018-02-08 HIGH 7.8 CVE-2017-16651 KEVEPSS 37% Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, i… Debian Linux after 1.1.9 Fix from $1,9502017-11-09