CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject NetappOracle6Active Iq Unified Manager FedoraMysql+3 moreJun 17, 2026 Jan 19, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows...Show more |
2Fedoraproject Grafana2Fedora GrafanaJun 17, 2026 Jan 18, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no ot...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJul 14, 2026 Jan 17, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for C...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJul 14, 2026 Jan 17, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2...Show more |
2Fedoraproject Phoronix Media2Fedora Phoronix Test SuiteJun 17, 2026 Jan 16, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) |
2Fedoraproject Owncloud2Fedora Owncloud Desktop ClientJun 17, 2026 Jan 15, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution. |
3Debian FedoraprojectLibreswan3Debian Linux FedoraLibreswanJun 17, 2026 Jan 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This...Show more |
2Fedoraproject Gnu2Fedora RecutilsJun 17, 2026 Jan 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. |
2Fedoraproject Gnu2Fedora RecutilsJun 17, 2026 Jan 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. |
2Fedoraproject Gnu2Fedora RecutilsJun 17, 2026 Jan 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. |
2Fedoraproject Marked Project2Fedora MarkedJun 17, 2026 Jan 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who...Show more |
2Fedoraproject Marked Project2Fedora MarkedJun 17, 2026 Jan 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). A...Show more |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Jan 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. |
4Debian FedoraprojectFlatpak+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At thi...Show more |
3Debian FedoraprojectZabbix3Debian Linux FedoraZabbixJun 17, 2026 Jan 13, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configur...Show more |
2Fedoraproject Zabbix2Fedora ZabbixJun 17, 2026 Jan 13, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for gr...Show more |
2Fedoraproject Zabbix2Fedora ZabbixJun 17, 2026 Jan 13, 2022 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permi...Show more |
2Fedoraproject Phoronix Media2Fedora Phoronix Test SuiteJun 17, 2026 Jan 13, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) |
2Fedoraproject Phoronix Media2Fedora Phoronix Test SuiteJun 17, 2026 Jan 13, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) |
4Debian FedoraprojectFlatpak+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jan 12, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the...Show more |