Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.0
CVE-2025-38051
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix use-after-free in cifs_fill_dirent
There is a race condition i…
Debian Linux
5.4.294 / 5.10.238+
HIGH 7.8
CVE-2024-52035
An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed…
Debian Linux
No fix yet
HIGH 7.8
CVE-2024-54028
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead …
Debian Linux
No fix yet
HIGH 8.8
CVE-2025-49113 KEVEPSS 98%
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n…
Debian Linux
1.5.10 / 1.6.11+
HIGH 8.8
CVE-2025-3887
GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…
Debian Linux
1.26.1+
HIGH 7.5
CVE-2025-47287
Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo…
Debian Linux
6.5.0+
HIGH 7.5
CVE-2024-47619
syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not a…
Debian Linux
4.8.2+
HIGH 7.5
CVE-2025-43965
In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.
Debian Linux
7.1.1-44+
CRITICAL 9.8
CVE-2025-2291
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to l…
Debian Linux
1.24.1+
MEDIUM 5.5
CVE-2025-29769
libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an al…
Debian Linux
8.16.1+
HIGH 7.4
CVE-2025-3155EPSS 13%
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious …
Debian Linux
No fix yet
HIGH 7.8
CVE-2023-52935
In the Linux kernel, the following vulnerability has been resolved:
mm/khugepaged: fix ->anon_vma race
If an ->anon_vma is attached to the VMA, col…
Debian Linux
5.4.299 / 5.10.243+
HIGH 7.8
CVE-2024-40635
containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched w…
Debian Linux
1.6.38 / 1.7.27+
HIGH 8.1
CVE-2025-27363 KEVEPSS 28%
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font sub…
Debian Linux
after 2.13.0
HIGH 8.8
CVE-2025-27516
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows …
Debian Linux
3.1.6+
HIGH 7.8
CVE-2025-1080
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice…
Debian Linux
24.8.5.1 / 25.2.1.1+
HIGH 7.4
CVE-2024-55581
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of …
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2025-0838
There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,ma…
Debian Linux
20250127.0+
HIGH 7.5
CVE-2025-25475
A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafte…
Debian Linux
Patch available
MEDIUM 6.5
CVE-2025-25474
DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.
Debian Linux
Patch available
MEDIUM 5.3
CVE-2025-25472
A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.
Debian Linux
Patch available
MEDIUM 6.5
CVE-2025-22921
FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.
Debian Linux
Mitigation only
CRITICAL 9.9
CVE-2025-0781
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating…
Debian Linux
after 2020.3.19
MEDIUM 6.5
CVE-2024-12426
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice.
…
Debian Linux
24.8.4+
HIGH 7.1
CVE-2024-53150 KEV
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Fix out of bounds reads when finding clock sources
The current…
Debian Linux
5.4.287 / 5.10.231+
CRITICAL 9.8
CVE-2024-47606
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_the…
Debian Linux
1.24.10+
MEDIUM 5.5
CVE-2024-53566
An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path …
Debian Linux
Mitigation only
HIGH 7.8
CVE-2024-53104 KEV
In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_forma…
Debian Linux
4.19.324 / 5.4.286+
HIGH 8.8
CVE-2024-44308 KEVEPSS 9%
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS…
Debian Linux
2.1.1 / 15.1.1+
MEDIUM 6.3
CVE-2024-44309 KEVEPSS 23%
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.…
Debian Linux
2.1.1 / 15.1.1+