Search CVE reports


Toggle filters

111 – 120 of 21762 results

Status is adjusted based on your filters.


CVE-2024-12224

Medium priority
Needs evaluation

[RUSTSEC-2024-0421]

1 affected package

rust-idna

Package 24.04 LTS
rust-idna Needs evaluation
Show less packages

CVE-2024-11053

Low priority
Fixed

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the...

1 affected package

curl

Package 24.04 LTS
curl Fixed
Show less packages

CVE-2024-54133

Medium priority
Needs evaluation

Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) vulnerability in the `content_security_policy` helper starting in version 5.2.0 of Action Pack and prior to...

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages

CVE-2024-46657

Medium priority
Needs evaluation

Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

1 affected package

mupdf

Package 24.04 LTS
mupdf Needs evaluation
Show less packages

CVE-2024-54152

Medium priority
Needs evaluation

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the...

1 affected package

angular.js

Package 24.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2024-55638

Medium priority

Not in release

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-55637

Medium priority

Not in release

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-55636

Medium priority

Not in release

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-55635

Medium priority

Not in release

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-55634

Medium priority

Not in release

A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages