Search CVE reports
111 – 120 of 26597 results
CVE-2024-51744
Medium priorityNot in release
golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if...
2 affected packages
golang-github-golang-jwt-jwt, golang-github-golang-jwt-jwt-v5
Package | 20.04 LTS |
---|---|
golang-github-golang-jwt-jwt | Not in release |
golang-github-golang-jwt-jwt-v5 | Not in release |
CVE-2024-51774
Medium priorityqBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
1 affected packages
qbittorrent
Package | 20.04 LTS |
---|---|
qbittorrent | Needs evaluation |
CVE-2024-21510
Medium priorityVersions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to...
1 affected packages
ruby-sinatra
Package | 20.04 LTS |
---|---|
ruby-sinatra | Vulnerable |
CVE-2024-51482
Medium priorityZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.64.
1 affected packages
zoneminder
Package | 20.04 LTS |
---|---|
zoneminder | Needs evaluation |
CVE-2024-48910
Medium priorityNot in release
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
1 affected packages
node-dompurify
Package | 20.04 LTS |
---|---|
node-dompurify | Not in release |
CVE-2024-10086
Medium priorityA vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.
1 affected packages
consul
Package | 20.04 LTS |
---|---|
consul | Needs evaluation |
CVE-2024-10006
Medium priorityA vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
1 affected packages
consul
Package | 20.04 LTS |
---|---|
consul | Needs evaluation |
CVE-2024-10005
Medium priorityA vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.
1 affected packages
consul
Package | 20.04 LTS |
---|---|
consul | Needs evaluation |
CVE-2024-48241
Medium priorityAn issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.
1 affected packages
radare2
Package | 20.04 LTS |
---|---|
radare2 | Needs evaluation |
CVE-2024-3935
Medium priorityIn Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping,...
1 affected packages
mosquitto
Package | 20.04 LTS |
---|---|
mosquitto | Needs evaluation |