Search CVE reports


Toggle filters

1 – 10 of 50 results


CVE-2025-51591

Medium priority
Needs evaluation

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe.

1 affected package

pandoc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-5889

Medium priority
Needs evaluation

A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient...

1 affected package

node-brace-expansion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-brace-expansion Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-9880

Medium priority
Ignored

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

1 affected package

pandas

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandas Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-45321

Medium priority
Needs evaluation

The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.

1 affected package

cpanminus

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cpanminus Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-42992

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

1 affected package

pandas

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandas Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-48623

Medium priority

Some fixes available 2 of 4

The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.

1 affected package

libcpanel-json-xs-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcpanel-json-xs-perl Not affected Fixed Fixed Needs evaluation
Show less packages

CVE-2023-38745

Medium priority
Needs evaluation

Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image element in the input when generating files via the --extract-media option or outputting to PDF format. This allows an attacker to...

1 affected package

pandoc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-33798

Medium priority
Needs evaluation

A null pointer dereference was found in libpano13, version libpano13-2.9.20. The flow allows attackers to cause a denial of service and potential code execute via a crafted file.

1 affected package

libpano13

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpano13 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-35936

Medium priority
Needs evaluation

Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.13 and prior to version 3.1.4, Pandoc is susceptible to an arbitrary file write...

1 affected package

pandoc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandoc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-47373

Medium priority
Needs evaluation

Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper...

1 affected package

pandora

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pandora Not in release Not in release Needs evaluation
Show less packages