Search CVE reports


Toggle filters

251 – 260 of 43262 results

Status is adjusted based on your filters.


CVE-2025-8713

Medium priority
Needs evaluation

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. ...

7 affected packages

postgresql-17, postgresql-16, postgresql-14, postgresql-12, postgresql-10...

Package 16.04 LTS
postgresql-17
postgresql-16
postgresql-14
postgresql-12
postgresql-10
postgresql-9.5 Needs evaluation
postgresql-9.3
Show all 7 packages Show less packages

CVE-2025-55197

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on...

2 affected packages

pypdf, pypdf2

Package 16.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2025-55193

Medium priority
Needs evaluation

Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may...

1 affected package

rails

Package 16.04 LTS
rails Needs evaluation
Show less packages

CVE-2012-10059

Medium priority
Needs evaluation

Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing...

1 affected package

dolibarr

Package 16.04 LTS
dolibarr Needs evaluation
Show less packages

CVE-2025-8770

Medium priority
Ignored

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2025-7739

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2025-7734

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2025-6186

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2025-5819

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated users with developer access to obtain ID tokens for...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2025-2937

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages