Search CVE reports
261 – 270 of 35526 results
Authlib is a Python library which builds OAuth and OpenID Connect servers. In version 1.6.5 and prior, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that...
1 affected package
python-authlib
| Package | 22.04 LTS |
|---|---|
| python-authlib | Needs evaluation |
Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be...
1 affected package
node-preact
| Package | 22.04 LTS |
|---|---|
| node-preact | Needs evaluation |
An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba shareThis issue affects smb4k: from ?...
1 affected package
smb4k
| Package | 22.04 LTS |
|---|---|
| smb4k | Needs evaluation |
An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper
1 affected package
smb4k
| Package | 22.04 LTS |
|---|---|
| smb4k | Needs evaluation |
Not in release
The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version...
1 affected package
rust-rsa
| Package | 22.04 LTS |
|---|---|
| rust-rsa | Not in release |
Not in release
Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsafe string formatting (Python %...
1 affected package
python-parsl
| Package | 22.04 LTS |
|---|---|
| python-parsl | Not in release |
Not in release
Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can...
1 affected package
miniflux
| Package | 22.04 LTS |
|---|---|
| miniflux | Not in release |
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests...
1 affected package
modsecurity-crs
| Package | 22.04 LTS |
|---|---|
| modsecurity-crs | Needs evaluation |
A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can...
2 affected packages
libsoup2.4, libsoup3
| Package | 22.04 LTS |
|---|---|
| libsoup2.4 | Vulnerable |
| libsoup3 | Vulnerable |
Not in release
llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is parsed directly from JSON input in the llama.cpp server's completion endpoints without validation to ensure it's...
1 affected package
llama.cpp
| Package | 22.04 LTS |
|---|---|
| llama.cpp | Not in release |