Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.8
CVE-2026-54230

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell …

Mitigation only
Fix from $1,950 2026-06-13
Fedora MEDIUM 5.5
CVE-2026-54231

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal …

Mitigation only
Fix from $1,600 2026-06-13
Fedora HIGH 8.8
CVE-2026-35093

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directorie…

Fix: 1.30.3 / 1.31.1+
Fix from $1,950 2026-04-01
Fedora MEDIUM 5.5
CVE-2026-35094

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulner…

Mitigation only
Fix from $1,600 2026-04-01
Fedora HIGH 8.8
CVE-2024-38276

Incorrect CSRF token checks resulted in multiple CSRF risks.

Fix: 4.1.10 / 4.2.8+
Fix from $1,950 2024-06-18
Fedora CRITICAL 9.8
CVE-2024-36048

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before …

Fix: 5.15.17 / 6.2.13+
Fix from $2,300 2024-05-18
Fedora HIGH 7.5
CVE-2024-31142EPSS 17%

Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Specul…

Fix: 4.15.6 / 4.16.6+
Fix from $1,950 2024-05-16
Fedora MEDIUM 6.5
CVE-2023-46842EPSS 9%

Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to p…

Patch available
Fix from $1,600 2024-05-16
Fedora MEDIUM 6.5
CVE-2024-3044

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt …

Fix: 7.6.7.1 / 24.2.3.1+
Fix from $1,600 2024-05-14
Fedora HIGH 7.5
CVE-2024-4854

MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet in…

Fix: after 4.2.4
Fix from $1,950 2024-05-14
Fedora CRITICAL 9.1
CVE-2024-34340

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set t…

Fix: 1.2.27+
Fix from $2,300 2024-05-14
Fedora HIGH 8.8
CVE-2024-31460

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.p…

Fix: 1.2.27+
Fix from $1,950 2024-05-14
Fedora HIGH 7.2
CVE-2024-31459

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.…

Fix: 1.2.27+
Fix from $1,950 2024-05-14
Fedora HIGH 8.0
CVE-2024-31458EPSS 13%

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function i…

Fix: 1.2.27+
Fix from $1,950 2024-05-14
Fedora HIGH 8.8
CVE-2024-31445EPSS 26%

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_ne…

Fix: 1.2.27+
Fix from $1,950 2024-05-14
Fedora MEDIUM 5.4
CVE-2024-31443

Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_…

Fix: 1.2.27+
Fix from $1,600 2024-05-14
Fedora MEDIUM 5.4
CVE-2024-31444EPSS 15%

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_f…

Fix: 1.2.27+
Fix from $1,600 2024-05-14
Fedora HIGH 7.8
CVE-2024-27398

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco conn…

Fix: 4.15 / 4.19.314+
Fix from $1,950 2024-05-14
Fedora HIGH 7.2
CVE-2024-25641EPSS 86%

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable …

Fix: 1.2.27+
Fix from $1,950 2024-05-14
Fedora MEDIUM 5.4
CVE-2024-34064

Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HT…

Fix: 3.1.4+
Fix from $1,600 2024-05-06
Fedora CRITICAL 9.8
CVE-2024-34502

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes wi…

Fix: 1.39.6 / 1.40.2+
Fix from $2,300 2024-05-05
Fedora HIGH 7.5
CVE-2024-34506

An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a use…

Fix: 1.39.7 / 1.40.3+
Fix from $1,950 2024-05-05
Fedora HIGH 7.4
CVE-2024-34507

An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XS…

Fix: 1.39.7 / 1.40.3+
Fix from $1,950 2024-05-05
Fedora MEDIUM 6.1
CVE-2024-34500

An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur t…

Fix: 1.39.6 / 1.40.2+
Fix from $1,600 2024-05-05
Fedora HIGH 8.6
CVE-2024-34402

An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultan…

Fix: after 0.9.7
Fix from $1,950 2024-05-03
Fedora MEDIUM 5.9
CVE-2024-34403

An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.

Fix: after 0.9.7
Fix from $1,600 2024-05-03
Fedora HIGH 7.5
CVE-2024-4140

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME mes…

Fix: 1.954+
Fix from $1,950 2024-05-02
Fedora CRITICAL 9.8
CVE-2023-47212

A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an o…

No fix yet
Fix from $2,300 2024-05-01
Fedora CRITICAL 9.8
CVE-2024-22391

A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially c…

No fix yet
Fix from $2,300 2024-04-25
Fedora MEDIUM 6.5
CVE-2024-25569

An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafte…

No fix yet
Fix from $1,600 2024-04-25