Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-30130 phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification. Debian Linux 2.0.31 / 3.0.7+ Fix from $1,9502021-04-06 CRITICAL 9.8 CVE-2021-30164 Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API. Debian Linux 4.0.8 / 4.1.2+ Fix from $2,3002021-04-06 HIGH 7.5 CVE-2021-30163 Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have chang… Debian Linux 4.0.8 / 4.1.2+ Fix from $1,9502021-04-06 MEDIUM 6.1 CVE-2020-36306 Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field. Debian Linux 4.0.7 / 4.1.1+ Fix from $1,6002021-04-06 MEDIUM 6.1 CVE-2020-36307 Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links. Debian Linux 4.0.7 / 4.1.1+ Fix from $1,6002021-04-06 MEDIUM 5.3 CVE-2019-25026 Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting. Debian Linux 3.4.13 / 4.0.6+ Fix from $1,6002021-04-06 MEDIUM 5.3 CVE-2020-36308 Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading ti… Debian Linux 4.0.7 / 4.1.1+ Fix from $1,6002021-04-06 MEDIUM 6.1 CVE-2021-30154 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* me… Debian Linux 1.31.12 / 1.35.2+ Fix from $1,6002021-04-06 MEDIUM 6.1 CVE-2021-30157 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChang… Debian Linux 1.31.12 / 1.35.2+ Fix from $1,6002021-04-06 MEDIUM 5.3 CVE-2021-30158 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. Thi… Debian Linux 1.31.12 / 1.35.2+ Fix from $1,6002021-04-06 MEDIUM 6.1 CVE-2021-30151 Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used. Debian Linux after 6.2.0 Fix from $1,6002021-04-06 CRITICAL 9.8 CVE-2021-20308 Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-… Debian Linux after 1.9.11 Fix from $2,3002021-04-05 CRITICAL 9.8 CVE-2021-1871 KEVEPSS 7% A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update… Debian Linux 10.15.7 / 11.2+ Fix from $2,3002021-04-02 MEDIUM 5.5 CVE-2020-10001 An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, … Debian Linux 11.1.0+ Fix from $1,6002021-04-02 MEDIUM 5.3 CVE-2021-20296 A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression f… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-04-01 MEDIUM 5.5 CVE-2021-3477 There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be … Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 MEDIUM 5.5 CVE-2021-3478 There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processe… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 MEDIUM 5.5 CVE-2021-3479 There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processe… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 MEDIUM 5.3 CVE-2021-3475 There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-30 MEDIUM 5.3 CVE-2021-3476 A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to Open… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-30 MEDIUM 5.3 CVE-2021-3474 There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHu… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-30 MEDIUM 5.9 CVE-2021-21409 Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol serv… Debian Linux 4.1.61+ Fix from $1,6002021-03-30 HIGH 7.5 CVE-2021-29376 ircII before 20210314 allows remote attackers to cause a denial of service (segmentation fault and client crash, disconnecting the victim from an IRC… Debian Linux 20210314+ Fix from $1,9502021-03-30 HIGH 7.2 CVE-2021-23358 The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template fu… Debian Linux 1.12.1 / 1.13.0-2+ Fix from $1,9502021-03-29 MEDIUM 5.3 CVE-2021-28963 Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters. Debian Linux 3.2.1+ Fix from $1,6002021-03-22 MEDIUM 6.1 CVE-2021-28957 An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the … Debian Linux 4.6.3+ Fix from $1,6002021-03-21 HIGH 8.6 CVE-2020-25097EPSS 8% An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Req… Debian Linux 4.14 / 5.0.5+ Fix from $1,9502021-03-19 HIGH 7.5 CVE-2021-27291 In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions… Debian Linux 2.7.4+ Fix from $1,9502021-03-17 HIGH 7.8 CVE-2017-20002 The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local user… Shadow No fix yet Fix from $1,9502021-03-17 HIGH 7.5 CVE-2021-28374 The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissio… Courier Authlib 0.71.1-2+ Fix from $1,9502021-03-15