CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jan 25, 2022 N/A· v4 4.6 MEDIUM· v3 4.7 MEDIUM· v2 Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jan 25, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of map...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jan 25, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to...Show more |
2Debian Freecadweb2Debian Linux FreecadJun 17, 2026 Jan 25, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document. |
2Debian Freecadweb2Debian Linux FreecadJun 17, 2026 Jan 25, 2022 N/A· v4 7.8 HIGH· v3 7.6 HIGH· v2 Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename. |
3Debian FedoraprojectLibrecad3Debian Linux FedoraLibrecadJun 17, 2026 Jan 25, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document. |
3Debian FedoraprojectLibrecad3Debian Linux FedoraLibrecadJun 17, 2026 Jan 25, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document. |
3Debian FedoraprojectLibrecad3Debian Linux FedoraLibrecadJun 17, 2026 Jan 25, 2022 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document. |
6Debian Libexpat ProjectNetapp+3 more7Clustered Data Ontap Communications Metasolv SolutionDebian Linux+4 moreJun 17, 2026 Jan 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. |
2Contribsys Debian2Debian Linux SidekiqJun 17, 2026 Jan 21, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users. |
2Cached Path Relative Project Debian2Cached Path Relative Debian LinuxJun 17, 2026 Jan 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the p...Show more |
3Apple DebianVim3Debian Linux MacosVimJun 17, 2026 Jan 21, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Out-of-bounds Read in vim/vim prior to 8.2. |
3Apple DebianVim3Debian Linux MacosVimJun 17, 2026 Jan 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based Buffer Overflow in vim/vim prior to 8.2. |
5Advanced Intrusion Detection Environment Project CanonicalDebian+2 more7Advanced Intrusion Detection Environment Debian LinuxEnterprise Linux+4 moreJun 17, 2026 Jan 20, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow. |
2Debian Log4js Project2Debian Linux Log4jsJun 17, 2026 Jan 19, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log...Show more |
3Debian FedoraprojectIpython3Debian Linux FedoraIpythonJun 17, 2026 Jan 19, 2022 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code ex...Show more |
2Cacti Debian2Cacti Debian LinuxJun 17, 2026 Jan 19, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php. |
2Debian Libspf2 Project2Debian Linux Libspf2Jun 17, 2026 Jan 19, 2022 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS re...Show more |
3Debian H2databaseOracle3Communications Cloud Native Core Console Debian LinuxH2Jun 17, 2026 Jan 19, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability...Show more |
3Debian NetappOracle197 Mode Transition Tool Active Iq Unified ManagerCloud Insights Acquisition Unit+16 moreJun 17, 2026 Jan 19, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise E...Show more |