Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 8.8
CVE-2022-24810

net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can us…

Fix: 5.9.2+
Fix from $1,950 2024-04-16
Debian Linux HIGH 8.6
CVE-2024-32487

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation…

Fix: after 653
Fix from $1,950 2024-04-13
Debian Linux MEDIUM 5.3
CVE-2024-28182EPSS 85%

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbound…

Fix: 1.61.0+
Fix from $1,600 2024-04-04
Debian Linux HIGH 7.8
CVE-2024-26739

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we'r…

Fix: 5.10.238 / 5.15.182+
Fix from $1,950 2024-04-03
Debian Linux HIGH 7.8
CVE-2023-52621

In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers These thre…

Fix: 5.10.237 / 5.15.181+
Fix from $1,950 2024-03-26
Debian Linux MEDIUM 5.3
CVE-2024-29025

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients…

Fix: 4.1.108+
Fix from $1,600 2024-03-25
Debian Linux HIGH 7.1
CVE-2024-30205

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

Fix: 9.6.23 / 29.3+
Fix from $1,950 2024-03-25
Debian Linux MEDIUM 5.5
CVE-2024-30203

In Emacs before 29.3, Gnus treats inline MIME contents as trusted.

Fix: 9.6.23 / 29.3+
Fix from $1,600 2024-03-25
Debian Linux MEDIUM 6.8
CVE-2024-28102

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service att…

Fix: 1.5.6+
Fix from $1,600 2024-03-21
Debian Linux HIGH 7.5
CVE-2023-52159

A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd da…

Fix: 1.0.4+
Fix from $1,950 2024-03-18
Debian Linux HIGH 7.5
CVE-2024-1936

The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local ca…

Fix: 115.8.1+
Fix from $1,950 2024-03-04
Debian Linux HIGH 7.8
CVE-2023-52572

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix UAF in cifs_demultiplex_thread() There is a UAF when xfstests on cifs…

Fix: 5.4.297 / 5.10.237+
Fix from $1,950 2024-03-02
Debian Linux HIGH 7.5
CVE-2024-27354

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate c…

Fix: 1.0.23 / 2.0.47+
Fix from $1,950 2024-03-01
Debian Linux HIGH 7.5
CVE-2024-27355

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a ce…

Fix: 1.0.23 / 2.0.47+
Fix from $1,950 2024-03-01
Debian Linux MEDIUM 6.5
CVE-2024-25082

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

Fix: after 20230101
Fix from $1,600 2024-02-26
Debian Linux HIGH 7.5
CVE-2024-22201

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out.…

Fix: 9.4.54 / 10.0.20+
Fix from $1,950 2024-02-26
Debian Linux MEDIUM 6.5
CVE-2023-52160

The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to…

Fix: after 2.10
Fix from $1,600 2024-02-22
Debian Linux HIGH 7.8
CVE-2024-26581

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on …

Fix: 5.4.269 / 5.10.210+
Fix from $1,950 2024-02-20
Debian Linux HIGH 7.5
CVE-2024-24814

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Re…

Fix: after 2.4.15.1
Fix from $1,950 2024-02-13
Debian Linux MEDIUM 5.5
CVE-2024-1151

A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursive…

Fix: after 6.7.8
Fix from $1,600 2024-02-11
Debian Linux CRITICAL 9.8
CVE-2024-25714

In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the compa…

Fix: after 1.1.3
Fix from $2,300 2024-02-11
Debian Linux CRITICAL 9.8
CVE-2024-25189

libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side cha…

No fix yet
Fix from $2,300 2024-02-08
Debian Linux MEDIUM 6.8
CVE-2024-24857

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity …

Fix: 6.7.12+
Fix from $1,600 2024-02-05
Debian Linux MEDIUM 5.3
CVE-2024-24858

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection o…

Fix: after 6.7.12
Fix from $1,600 2024-02-05
Debian Linux CRITICAL 9.8
CVE-2024-0808

Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious f…

Fix: 121.0.6167.85+
Fix from $2,300 2024-01-24
Debian Linux MEDIUM 5.9
CVE-2024-20926

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Sup…

Patch available
Fix from $1,600 2024-01-16
Debian Linux HIGH 7.4
CVE-2024-20918

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo…

Patch available
Fix from $1,950 2024-01-16
Debian Linux MEDIUM 5.3
CVE-2024-22049

httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted…

Fix: 0.21.0+
Fix from $1,600 2024-01-04
Debian Linux HIGH 7.0
CVE-2023-6270

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct n…

Fix: 6.9+
Fix from $1,950 2024-01-04
Debian Linux HIGH 7.8
CVE-2023-7101 KEVEPSS 17%

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut…

Fix: after 0.65
Fix from $1,950 2023-12-24