Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

111 – 120 of 26597 results

Status is adjusted based on your filters.


CVE-2024-51744

Medium priority

Not in release

golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if...

2 affected packages

golang-github-golang-jwt-jwt, golang-github-golang-jwt-jwt-v5

Package 20.04 LTS
golang-github-golang-jwt-jwt Not in release
golang-github-golang-jwt-jwt-v5 Not in release
Show less packages

CVE-2024-51774

Medium priority
Needs evaluation

qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.

1 affected packages

qbittorrent

Package 20.04 LTS
qbittorrent Needs evaluation
Show less packages

CVE-2024-21510

Medium priority
Vulnerable

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to...

1 affected packages

ruby-sinatra

Package 20.04 LTS
ruby-sinatra Vulnerable
Show less packages

CVE-2024-51482

Medium priority
Needs evaluation

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.64.

1 affected packages

zoneminder

Package 20.04 LTS
zoneminder Needs evaluation
Show less packages

CVE-2024-48910

Medium priority

Not in release

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.

1 affected packages

node-dompurify

Package 20.04 LTS
node-dompurify Not in release
Show less packages

CVE-2024-10086

Medium priority
Needs evaluation

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.

1 affected packages

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2024-10006

Medium priority
Needs evaluation

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

1 affected packages

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2024-10005

Medium priority
Needs evaluation

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.

1 affected packages

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2024-48241

Medium priority
Needs evaluation

An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.

1 affected packages

radare2

Package 20.04 LTS
radare2 Needs evaluation
Show less packages

CVE-2024-3935

Medium priority
Needs evaluation

In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping,...

1 affected packages

mosquitto

Package 20.04 LTS
mosquitto Needs evaluation
Show less packages