Search CVE reports


Toggle filters

21 – 30 of 39436 results

Status is adjusted based on your filters.


CVE-2025-58121

Medium priority
Needs evaluation

Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information

1 affected package

check-mk

Package 18.04 LTS
check-mk Needs evaluation
Show less packages

CVE-2025-10158

Medium priority
Needs evaluation

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync...

1 affected package

rsync

Package 18.04 LTS
rsync Needs evaluation
Show less packages

CVE-2025-64756

Medium priority
Not affected

Glob matches files using patterns the shell uses. From versions 10.3.7 to 11.0.3, the glob CLI contains a command injection vulnerability in its -c/--cmd option that allows arbitrary command execution when processing files with...

1 affected package

node-glob

Package 18.04 LTS
node-glob Not affected
Show less packages

CVE-2025-13193

Medium priority
Needs evaluation

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information...

1 affected package

libvirt

Package 18.04 LTS
libvirt Needs evaluation
Show less packages

CVE-2025-63745

Medium priority
Needs evaluation

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool...

1 affected package

radare2

Package 18.04 LTS
radare2 Needs evaluation
Show less packages

CVE-2025-63744

Medium priority
Needs evaluation

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.

1 affected package

radare2

Package 18.04 LTS
radare2 Needs evaluation
Show less packages

CVE-2025-47913

Medium priority
Needs evaluation

SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 18.04 LTS
golang-go.crypto Needs evaluation
snapd Needs evaluation
lxd Needs evaluation
google-guest-agent Needs evaluation
Show less packages

CVE-2025-64718

Medium priority
Needs evaluation

js-yaml is a JavaScript YAML parser and dumper. In js-yaml 4.1.0 and below, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse...

1 affected package

node-js-yaml

Package 18.04 LTS
node-js-yaml Needs evaluation
Show less packages

CVE-2025-13120

Medium priority
Needs evaluation

A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approached locally. The exploit has been...

1 affected package

mruby

Package 18.04 LTS
mruby Needs evaluation
Show less packages

CVE-2025-12818

Medium priority
Needs evaluation

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results...

8 affected packages

postgresql-18, postgresql-17, postgresql-16, postgresql-14, postgresql-12...

Package 18.04 LTS
postgresql-18
postgresql-17
postgresql-16
postgresql-14
postgresql-12
postgresql-10 Needs evaluation
postgresql-9.5
postgresql-9.3
Show all 8 packages Show less packages