Search CVE reports


Toggle filters

61 – 70 of 26149 results

Status is adjusted based on your filters.


CVE-2025-6493

Medium priority
Needs evaluation

A vulnerability was found in CodeMirror up to 5.17.0 and classified as problematic. Affected by this issue is some unknown functionality of the file mode/markdown/markdown.js of the component Markdown Mode. The manipulation leads...

1 affected package

codemirror-js

Package 24.04 LTS
codemirror-js Needs evaluation
Show less packages

CVE-2025-6490

Medium priority
Vulnerable

A vulnerability was found in sparklemotion nokogiri up to 1.18.7 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based...

1 affected package

ruby-nokogiri

Package 24.04 LTS
ruby-nokogiri Vulnerable
Show less packages

CVE-2025-6375

Medium priority
Needs evaluation

A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is the function MultipartInputStream of the file Net/src/MultipartReader.cpp. The manipulation leads to null pointer...

1 affected package

poco

Package 24.04 LTS
poco Needs evaluation
Show less packages

CVE-2025-48945

Medium priority
Needs evaluation

pycares is a Python module which provides an interface to c-ares. c-ares is a C library that performs DNS requests and name resolutions asynchronously. Prior to version 4.9.0, pycares is vulnerable to a use-after-free...

1 affected package

pycares

Package 24.04 LTS
pycares Needs evaluation
Show less packages

CVE-2024-4994

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2024-4025

Medium priority

Not in release

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2025-5121

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2025-2443

Medium priority

Not in release

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2025-44203

Medium priority
Needs evaluation

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the...

1 affected package

hoteldruid

Package 24.04 LTS
hoteldruid Needs evaluation
Show less packages

CVE-2024-7586

Medium priority

Not in release

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages