Search CVE reports


Toggle filters

371 – 380 of 36093 results

Status is adjusted based on your filters.


CVE-2025-24293

Medium priority
Needs evaluation

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three...

1 affected package

rails

Package 22.04 LTS
rails Needs evaluation
Show less packages

CVE-2025-11175

Medium priority
Needs evaluation

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular...

1 affected package

mediawiki

Package 22.04 LTS
mediawiki Needs evaluation
Show less packages

CVE-2025-69662

Medium priority
Needs evaluation

SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.

1 affected package

python-geopandas

Package 22.04 LTS
python-geopandas Needs evaluation
Show less packages

CVE-2025-62349

Medium priority
Needs evaluation

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and...

1 affected package

salt

Package 22.04 LTS
salt Needs evaluation
Show less packages

CVE-2025-62348

Medium priority
Needs evaluation

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

1 affected package

salt

Package 22.04 LTS
salt Needs evaluation
Show less packages

CVE-2025-15497

Medium priority
Not affected

Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service

1 affected package

openvpn

Package 22.04 LTS
openvpn Not affected
Show less packages

CVE-2020-37014

Medium priority

Not in release

Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in...

1 affected package

tryton-sao

Package 22.04 LTS
tryton-sao Not in release
Show less packages

CVE-2020-36966

Medium priority

Not in release

Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and...

1 affected package

dolibarr

Package 22.04 LTS
dolibarr Not in release
Show less packages

CVE-2026-25128

Medium priority

Not in release

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.3.6 through 5.3.3, a RangeError vulnerability exists in the numeric...

1 affected package

node-webfont

Package 22.04 LTS
node-webfont Not in release
Show less packages

CVE-2024-4027

Medium priority
Needs evaluation

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by...

1 affected package

undertow

Package 22.04 LTS
undertow Needs evaluation
Show less packages