Search CVE reports


Toggle filters

1 – 10 of 1750 results


CVE-2025-6536

Medium priority
Needs evaluation

A vulnerability has been found in Tarantool up to 3.3.1 and classified as problematic. Affected by this vulnerability is the function tm_to_datetime in the library src/lib/core/datetime.c. The manipulation leads to...

1 affected package

tarantool

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tarantool Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-34075

Negligible priority
Not affected

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Initially assigned to document an issues that allows guest VM to modify the host’s Vagrantfile via default synced folder, leading to...

1 affected package

vagrant

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vagrant Not in release Not affected Not affected Not affected
Show less packages

CVE-2025-29786

Medium priority
Needs evaluation

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, it will attempt to compile the entire string and generate an Abstract...

1 affected package

golang-github-antonmedv-expr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-antonmedv-expr Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-6388

Medium priority

Some fixes available 5 of 6

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.

1 affected package

ubuntu-advantage-desktop-daemon

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ubuntu-advantage-desktop-daemon Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-54662

Medium priority
Vulnerable

Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.

1 affected package

dante

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dante Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-3772

Medium priority

Some fixes available 2 of 3

Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

1 affected package

pydantic

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pydantic Not affected Fixed Fixed
Show less packages

CVE-2024-23635

Medium priority
Needs evaluation

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML...

1 affected package

libowasp-antisamy-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libowasp-antisamy-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-13939

Medium priority
Needs evaluation

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different,...

1 affected package

libstring-compare-constanttime-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libstring-compare-constanttime-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-43643

Medium priority
Needs evaluation

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of...

1 affected package

libowasp-antisamy-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libowasp-antisamy-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-3432

Medium priority
Ignored

Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.

1 affected package

plantuml

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
plantuml Not affected Not affected Not affected Not affected
Show less packages