Search CVE reports


Toggle filters

41 – 50 of 25599 results

Status is adjusted based on your filters.


CVE-2025-49113

Medium priority
Needs evaluation

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP...

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2025-49112

Medium priority
Needs evaluation

setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.

3 affected packages

redict, redis, valkey

Package 24.04 LTS
redict Not in release
redis Needs evaluation
valkey Needs evaluation
Show less packages

CVE-2025-48995

Medium priority

Not in release

SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set...

1 affected package

python-signxml

Package 24.04 LTS
python-signxml Not in release
Show less packages

CVE-2025-48994

Medium priority

Not in release

SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set...

1 affected package

python-signxml

Package 24.04 LTS
python-signxml Not in release
Show less packages

CVE-2025-48866

Medium priority
Needs evaluation

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The...

1 affected package

modsecurity-apache

Package 24.04 LTS
modsecurity-apache Needs evaluation
Show less packages

CVE-2025-48387

Medium priority
Needs evaluation

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9,...

1 affected package

node-tar-fs

Package 24.04 LTS
node-tar-fs Needs evaluation
Show less packages

CVE-2025-46807

Medium priority
Needs evaluation

A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny legitimate users service.This issue affects sslh before 2.2.4.

1 affected package

sslh

Package 24.04 LTS
sslh Needs evaluation
Show less packages

CVE-2025-46806

Medium priority
Needs evaluation

A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4.

1 affected package

sslh

Package 24.04 LTS
sslh Needs evaluation
Show less packages

CVE-2025-29785

Medium priority
Needs evaluation

quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release can be used to trigger a nil-pointer dereference by a malicious QUIC client. In order to...

1 affected package

golang-github-lucas-clemente-quic-go

Package 24.04 LTS
golang-github-lucas-clemente-quic-go Needs evaluation
Show less packages

CVE-2024-54028

Medium priority
Needs evaluation

An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to...

1 affected package

catdoc

Package 24.04 LTS
catdoc Needs evaluation
Show less packages