CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mariadb2Debian Linux MariadbJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. |
2Debian Mariadb2Debian Linux MariadbJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. |
2Debian Mariadb2Debian Linux MariadbJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. |
2Debian Mariadb2Debian Linux MariadbJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements. |
2Debian Mariadb2Debian Linux MariadbJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements. |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Apr 12, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted part...Show more |
4Apache AppleDebian+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn se...Show more |
4Apache AppleDebian+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Apr 12, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied...Show more |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Apr 12, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options ar...Show more |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Apr 12, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Apr 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents...Show more |
3Debian LinuxNetapp13Debian Linux H300e FirmwareH300s Firmware+10 moreJun 17, 2026 Apr 11, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. |
2Debian Pjsip2Debian Linux PjsipJun 17, 2026 Apr 6, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.12 and prior affects applications that use PJSIP DNS resolution. It doesn't affect PJSIP users...Show more |
2Debian Pjsip2Debian Linux PjsipJun 17, 2026 Apr 6, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that dire...Show more |
2Debian Wisc2Debian Linux HtcondorJun 17, 2026 Apr 6, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity whe...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.0 HIGH· v3 6.2 MEDIUM· v2 race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xe...Show more |