Search CVE reports


Toggle filters

1 – 10 of 465 results


CVE-2025-54310

Medium priority
Needs evaluation

qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.

1 affected package

qbittorrent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qbittorrent Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-49140

Medium priority
Needs evaluation

Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a bug in a RTP packet factory that can be exploited to trigger a panic with Pion based SFU via crafted RTP...

1 affected package

golang-github-pion-interceptor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-pion-interceptor Needs evaluation Not in release
Show less packages

CVE-2025-35036

Medium priority
Needs evaluation

Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive...

2 affected packages

libhibernate-validator-java, libhibernate-validator4-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhibernate-validator-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libhibernate-validator4-java Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-47287

Medium priority

Some fixes available 4 of 7

Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows...

1 affected package

python-tornado

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Fixed Fixed Ignored Ignored
Show less packages

CVE-2025-4287

Medium priority
Needs evaluation

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is...

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release
Show less packages

CVE-2025-32434

Medium priority
Not affected

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability...

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not affected
Show less packages

CVE-2025-3730

Medium priority
Needs evaluation

A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An...

1 affected package

pytorch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Not in release Needs evaluation Not in release
Show less packages

CVE-2025-30714

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network...

1 affected package

mysql-connector-python

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-python Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-30706

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access...

1 affected package

mysql-connector-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-java Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-32807

Medium priority
Needs evaluation

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

1 affected package

fusiondirectory

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fusiondirectory Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages