Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-54230 A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell … Fedora Mitigation only Fix from $1,9502026-06-13 MEDIUM 5.5 CVE-2026-54231 A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal … Fedora Mitigation only Fix from $1,6002026-06-13 HIGH 8.8 CVE-2026-35093 A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directorie… Fedora 1.30.3 / 1.31.1+ Fix from $1,9502026-04-01 MEDIUM 5.5 CVE-2026-35094 A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulner… Fedora Mitigation only Fix from $1,6002026-04-01 HIGH 8.8 CVE-2024-38276 Incorrect CSRF token checks resulted in multiple CSRF risks. Fedora 4.1.10 / 4.2.8+ Fix from $1,9502024-06-18 CRITICAL 9.8 CVE-2024-36048 QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before … Fedora 5.15.17 / 6.2.13+ Fix from $2,3002024-05-18 HIGH 7.5 CVE-2024-31142EPSS 17% Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Specul… Fedora 4.15.6 / 4.16.6+ Fix from $1,9502024-05-16 MEDIUM 6.5 CVE-2023-46842EPSS 9% Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to p… Fedora Patch available Fix from $1,6002024-05-16 MEDIUM 6.5 CVE-2024-3044 Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt … Fedora 7.6.7.1 / 24.2.3.1+ Fix from $1,6002024-05-14 HIGH 7.5 CVE-2024-4854 MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet in… Fedora after 4.2.4 Fix from $1,9502024-05-14 CRITICAL 9.1 CVE-2024-34340 Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set t… Fedora 1.2.27+ Fix from $2,3002024-05-14 HIGH 8.8 CVE-2024-31460 Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.p… Fedora 1.2.27+ Fix from $1,9502024-05-14 HIGH 7.2 CVE-2024-31459 Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.… Fedora 1.2.27+ Fix from $1,9502024-05-14 HIGH 8.0 CVE-2024-31458EPSS 13% Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function i… Fedora 1.2.27+ Fix from $1,9502024-05-14 HIGH 8.8 CVE-2024-31445EPSS 26% Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_ne… Fedora 1.2.27+ Fix from $1,9502024-05-14 MEDIUM 5.4 CVE-2024-31443 Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_… Fedora 1.2.27+ Fix from $1,6002024-05-14 MEDIUM 5.4 CVE-2024-31444EPSS 15% Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_f… Fedora 1.2.27+ Fix from $1,6002024-05-14 HIGH 7.8 CVE-2024-27398 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco conn… Fedora 4.15 / 4.19.314+ Fix from $1,9502024-05-14 HIGH 7.2 CVE-2024-25641EPSS 86% Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable … Fedora 1.2.27+ Fix from $1,9502024-05-14 MEDIUM 5.4 CVE-2024-34064 Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HT… Fedora 3.1.4+ Fix from $1,6002024-05-06 CRITICAL 9.8 CVE-2024-34502 An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes wi… Fedora 1.39.6 / 1.40.2+ Fix from $2,3002024-05-05 HIGH 7.5 CVE-2024-34506 An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a use… Fedora 1.39.7 / 1.40.3+ Fix from $1,9502024-05-05 HIGH 7.4 CVE-2024-34507 An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XS… Fedora 1.39.7 / 1.40.3+ Fix from $1,9502024-05-05 MEDIUM 6.1 CVE-2024-34500 An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur t… Fedora 1.39.6 / 1.40.2+ Fix from $1,6002024-05-05 HIGH 8.6 CVE-2024-34402 An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultan… Fedora after 0.9.7 Fix from $1,9502024-05-03 MEDIUM 5.9 CVE-2024-34403 An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string. Fedora after 0.9.7 Fix from $1,6002024-05-03 HIGH 7.5 CVE-2024-4140 An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME mes… Fedora 1.954+ Fix from $1,9502024-05-02 CRITICAL 9.8 CVE-2023-47212 A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an o… Fedora No fix yet Fix from $2,3002024-05-01 CRITICAL 9.8 CVE-2024-22391 A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially c… Fedora No fix yet Fix from $2,3002024-04-25 MEDIUM 6.5 CVE-2024-25569 An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafte… Fedora No fix yet Fix from $1,6002024-04-25