CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0...Show more |
2Debian Prometheus2Alertmanager Debian LinuxJun 17, 2026 Aug 25, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 23, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 23, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) |
3Debian NetappPython4Active Iq Unified Manager Converged Systems Advisor AgentDebian Linux+1 moreJun 17, 2026 Aug 22, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest. |
2Debian Python2Debian Linux PythonJun 17, 2026 Aug 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities. |
A use-after-free exists in Python through 3.9 via heappushpop in heapq. |
2Debian File Project2Debian Linux FileJun 17, 2026 Aug 22, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project. |
2Busybox Debian2Busybox Debian LinuxJul 14, 2026 Aug 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. |
2Apache Debian2Debian Linux Xml Graphics BatikJun 17, 2026 Aug 22, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it dire...Show more |
2Apache Debian2Debian Linux Xml Graphics BatikJun 17, 2026 Aug 22, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading externa...Show more |
2Debian Freedesktop2Debian Linux PopplerJun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file. |
2Debian Freedesktop2Debian Linux PopplerJun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog pro...Show more |
2Debian Gnu2Debian Linux Gnu Scientific LibraryJun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_...Show more |
2Debian Freedesktop2Debian Linux PopplerJun 17, 2026 Aug 22, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input. |
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c. |
4Debian GnuInvisible Island+1 more4Active Iq Unified Manager Debian LinuxNcurses+1 moreJul 23, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. |
In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a l...Show more |