Search CVE reports


Toggle filters

191 – 200 of 33401 results

Status is adjusted based on your filters.


CVE-2025-26625

Medium priority
Needs evaluation

Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with the contents of Git LFS objects, certain Git LFS commands may write to files...

1 affected package

git-lfs

Package 22.04 LTS
git-lfs Needs evaluation
Show less packages

CVE-2025-12004

Medium priority
Needs evaluation

(Incorrect Permission Assignment for Critical Resource vulnerability in ...)

1 affected package

mediawiki

Package 22.04 LTS
mediawiki Needs evaluation
Show less packages

CVE-2025-11979

Medium priority

Not in release

An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server v7.0 versions prior...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2025-11680

Medium priority
Needs evaluation

Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a...

1 affected package

libwebsockets

Package 22.04 LTS
libwebsockets Needs evaluation
Show less packages

CVE-2025-11679

Medium priority
Needs evaluation

Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a...

1 affected package

libwebsockets

Package 22.04 LTS
libwebsockets Needs evaluation
Show less packages

CVE-2025-11678

Medium priority
Needs evaluation

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request...

1 affected package

libwebsockets

Package 22.04 LTS
libwebsockets Needs evaluation
Show less packages

CVE-2025-11677

Medium priority
Needs evaluation

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function...

1 affected package

libwebsockets

Package 22.04 LTS
libwebsockets Needs evaluation
Show less packages

CVE-2024-31573

Medium priority
Needs evaluation

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.

1 affected package

xmlunit

Package 22.04 LTS
xmlunit Needs evaluation
Show less packages

CVE-2014-6439

Medium priority

Not in release

(Cross-site scripting (XSS) vulnerability in the CORS functionality in ...)

1 affected package

elasticsearch

Package 22.04 LTS
elasticsearch Not in release
Show less packages

CVE-2025-6338

Medium priority
Not affected

There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.

1 affected package

qt6-base

Package 22.04 LTS
qt6-base Not affected
Show less packages