Search CVE reports


Toggle filters

1 – 10 of 28306 results

Status is adjusted based on your filters.


CVE-2024-53868

Medium priority
Needs evaluation

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10...

1 affected package

trafficserver

Package 22.04 LTS
trafficserver Needs evaluation
Show less packages

CVE-2024-39780

Medium priority
Needs evaluation

A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions...

1 affected package

ros-dynamic-reconfigure

Package 22.04 LTS
ros-dynamic-reconfigure Needs evaluation
Show less packages

CVE-2025-27556

Medium priority
Not affected

Potential denial-of-service vulnerability in LoginView, LogoutView, and set_language() on Windows

1 affected package

python-django

Package 22.04 LTS
python-django Not affected
Show less packages

CVE-2024-45700

Medium priority
Needs evaluation

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and...

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2024-45699

Medium priority
Needs evaluation

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output...

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2024-42325

Medium priority
Needs evaluation

Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2024-36469

Medium priority
Needs evaluation

Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2024-36465

Medium priority
Needs evaluation

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2025-3074

Medium priority
Not affected

Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-3073

Medium priority
Not affected

Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security...

1 affected package

chromium-browser

Package 22.04 LTS
chromium-browser Not affected
Show less packages