CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Dec 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring. |
4Canonical DebianGnome+1 more4Debian Linux NetworkmanagerOpensuse+1 moreNov 21, 2024 Dec 26, 2019 N/A· v4 4.4 MEDIUM· v3 3.3 LOW· v2 In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network. |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 26, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential fo...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Dec 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affecte...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Dec 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post i...Show more |
4Debian LinuxNetapp+1 more13Active Iq Unified Manager Aff Baseboard Management ControllerCloud Backup+10 moreJun 17, 2026 Dec 25, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655. |
5Canonical DebianLinux+2 more168300 Firmware 8700 FirmwareA400 Firmware+13 moreJun 17, 2026 Dec 25, 2019 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f7...Show more |
8Debian NetappOpensuse+5 more11Backports Sle Cloud BackupDebian Linux+8 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive. |
7Canonical DebianFedoraproject+4 more12Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+9 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. |
8Debian NetappOpensuse+5 more11Backports Sle Cloud BackupDebian Linux+8 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results). |
3Debian GraphicsmagickOpensuse4Backports Debian LinuxGraphicsmagick+1 moreJun 17, 2026 Dec 24, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c. |
3Debian GraphicsmagickOpensuse4Backports Debian LinuxGraphicsmagick+1 moreJun 17, 2026 Dec 24, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c. |
3Debian GraphicsmagickOpensuse4Backports Debian LinuxGraphicsmagick+1 moreJun 17, 2026 Dec 24, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Dec 24, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Dec 24, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c. |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff Baseboard Management ControllerCloud Backup+10 moreJun 17, 2026 Dec 24, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c. |
5Canonical DebianLinux+2 more168300 Firmware 8700 FirmwareA400 Firmware+13 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the require...Show more |
3Canonical DebianSkolelinux4Debian Edu Config Debian Lan ConfigDebian Linux+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for o...Show more |
6Apache CanonicalDebian+3 more6Debian Linux LeapOncommand System Manager+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manip...Show more |
5Apache CanonicalDebian+2 more11Agile Engineering Data Management Debian LinuxHyperion Infrastructure Technology+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more |