CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Clamav Debian2Clamav Debian LinuxJun 17, 2026 Apr 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 7, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many en...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 7, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 6, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite point...Show more |
2Debian Phpseclib2Debian Linux PhpseclibJun 17, 2026 Apr 6, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification. |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vu...Show more |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS. |
2Contribsys Debian2Debian Linux SidekiqJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used. |
2Debian Htmldoc Project2Debian Linux HtmldocJun 17, 2026 Apr 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181. |
3Debian FedoraprojectLibpano13 Project3Debian Linux FedoraLibpano13Jun 17, 2026 Apr 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values. |
5Debian FedoraprojectNetapp+2 more6Active Iq Unified Manager Debian LinuxEnterprise Linux+3 moreJun 17, 2026 Apr 5, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called wi...Show more |
3Apple DebianFedoraproject6Debian Linux FedoraIpados+3 moreJun 17, 2026 Apr 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be ab...Show more |