Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.0
CVE-2025-38051

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_fill_dirent There is a race condition i…

Fix: 5.4.294 / 5.10.238+
Fix from $1,950 2025-06-18
Debian Linux HIGH 7.8
CVE-2024-52035

An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed…

No fix yet
Fix from $1,950 2025-06-02
Debian Linux HIGH 7.8
CVE-2024-54028

An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead …

No fix yet
Fix from $1,950 2025-06-02
Debian Linux HIGH 8.8
CVE-2025-49113 KEVEPSS 98%

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n…

Fix: 1.5.10 / 1.6.11+
Fix from $1,950 2025-06-02
Debian Linux HIGH 8.8
CVE-2025-3887

GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…

Fix: 1.26.1+
Fix from $1,950 2025-05-22
Debian Linux HIGH 7.5
CVE-2025-47287

Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo…

Fix: 6.5.0+
Fix from $1,950 2025-05-15
Debian Linux HIGH 7.5
CVE-2024-47619

syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not a…

Fix: 4.8.2+
Fix from $1,950 2025-05-07
Debian Linux HIGH 7.5
CVE-2025-43965

In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.

Fix: 7.1.1-44+
Fix from $1,950 2025-04-23
Debian Linux CRITICAL 9.8
CVE-2025-2291

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to l…

Fix: 1.24.1+
Fix from $2,300 2025-04-16
Debian Linux MEDIUM 5.5
CVE-2025-29769

libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an al…

Fix: 8.16.1+
Fix from $1,600 2025-04-07
Debian Linux HIGH 7.4
CVE-2025-3155EPSS 13%

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious …

No fix yet
Fix from $1,950 2025-04-03
Debian Linux HIGH 7.8
CVE-2023-52935

In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: fix ->anon_vma race If an ->anon_vma is attached to the VMA, col…

Fix: 5.4.299 / 5.10.243+
Fix from $1,950 2025-03-27
Debian Linux HIGH 7.8
CVE-2024-40635

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched w…

Fix: 1.6.38 / 1.7.27+
Fix from $1,950 2025-03-17
Debian Linux HIGH 8.1
CVE-2025-27363 KEVEPSS 28%

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font sub…

Fix: after 2.13.0
Fix from $1,950 2025-03-11
Debian Linux HIGH 8.8
CVE-2025-27516

Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows …

Fix: 3.1.6+
Fix from $1,950 2025-03-05
Debian Linux HIGH 7.8
CVE-2025-1080

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice…

Fix: 24.8.5.1 / 25.2.1.1+
Fix from $1,950 2025-03-04
Debian Linux HIGH 7.4
CVE-2024-55581

When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of …

No fix yet
Fix from $1,950 2025-02-26
Debian Linux CRITICAL 9.8
CVE-2025-0838

There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,ma…

Fix: 20250127.0+
Fix from $2,300 2025-02-21
Debian Linux HIGH 7.5
CVE-2025-25475

A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafte…

Patch available
Fix from $1,950 2025-02-18
Debian Linux MEDIUM 6.5
CVE-2025-25474

DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.

Patch available
Fix from $1,600 2025-02-18
Debian Linux MEDIUM 5.3
CVE-2025-25472

A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.

Patch available
Fix from $1,600 2025-02-18
Debian Linux MEDIUM 6.5
CVE-2025-22921

FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.

Mitigation only
Fix from $1,600 2025-02-18
Debian Linux CRITICAL 9.9
CVE-2025-0781

An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating…

Fix: after 2020.3.19
Fix from $2,300 2025-01-28
Debian Linux MEDIUM 6.5
CVE-2024-12426

Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. …

Fix: 24.8.4+
Fix from $1,600 2025-01-07
Debian Linux HIGH 7.1
CVE-2024-53150 KEV

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current…

Fix: 5.4.287 / 5.10.231+
Fix from $1,950 2024-12-24
Debian Linux CRITICAL 9.8
CVE-2024-47606

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_the…

Fix: 1.24.10+
Fix from $2,300 2024-12-12
Debian Linux MEDIUM 5.5
CVE-2024-53566

An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path …

Mitigation only
Fix from $1,600 2024-12-02
Debian Linux HIGH 7.8
CVE-2024-53104 KEV

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_forma…

Fix: 4.19.324 / 5.4.286+
Fix from $1,950 2024-12-02
Debian Linux HIGH 8.8
CVE-2024-44308 KEVEPSS 9%

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS…

Fix: 2.1.1 / 15.1.1+
Fix from $1,950 2024-11-20
Debian Linux MEDIUM 6.3
CVE-2024-44309 KEVEPSS 23%

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.…

Fix: 2.1.1 / 15.1.1+
Fix from $1,600 2024-11-20