CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
2Debian Python2Debian Linux PillowJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used. |
2Debian Python2Debian Linux PillowJun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. |
2Debian Python2Debian Linux PillowJun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. |
2Debian Htmldoc Project2Debian Linux HtmldocJun 17, 2026 Jan 10, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file. |
3Debian H2databaseOracle3Communications Cloud Native Core Policy Debian LinuxH2Jun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI serve...Show more |
2Debian Sphinxsearch2Debian Linux SphinxJun 17, 2026 Jan 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jan 6, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to b...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jan 6, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditio...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Jan 6, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform s...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jan 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugin...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 6, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data pa...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jan 6, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data pa...Show more |
2Debian Lighttpd2Debian Linux LighttpdJun 17, 2026 Jan 6, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash...Show more |
2Debian Roundcube2Debian Linux RoundcubeJun 17, 2026 Jan 6, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences. |
4Debian FedoraprojectOpensuse+1 more7Backports Debian LinuxExtra Packages For Enterprise Linux+4 moreJun 17, 2026 Jan 6, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. |
4Debian FedoraprojectOpensuse+1 more7Backports Debian LinuxExtra Packages For Enterprise Linux+4 moreJun 17, 2026 Jan 6, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. |