Search CVE reports


Toggle filters

1 – 10 of 27965 results

Status is adjusted based on your filters.


CVE-2025-24814

Medium priority
Needs evaluation

Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are...

1 affected package

lucene-solr

Package 20.04 LTS
lucene-solr Needs evaluation
Show less packages

CVE-2025-24359

Medium priority
Needs evaluation

ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute arbitrary Python code in the...

1 affected package

python-asteval

Package 20.04 LTS
python-asteval Needs evaluation
Show less packages

CVE-2025-22620

Medium priority

Not in release

(gitoxide is an implementation of git written in Rust. Prior to 0.17.0, ...)

1 affected package

rust-gix-worktree-state

Package 20.04 LTS
rust-gix-worktree-state Not in release
Show less packages

CVE-2025-22153

Medium priority
Needs evaluation

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Via a type confusion bug in versions of the CPython interpreter starting in 3.11...

1 affected package

restrictedpython

Package 20.04 LTS
restrictedpython Needs evaluation
Show less packages

CVE-2025-21548

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network...

1 affected package

mysql-connector-python

Package 20.04 LTS
mysql-connector-python Needs evaluation
Show less packages

CVE-2025-0611

Medium priority
Not affected

Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 20.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-0314

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.

1 affected package

gitlab

Package 20.04 LTS
gitlab Not in release
Show less packages

CVE-2024-9979

Medium priority

Not in release

(A flaw was found in PyO3. This vulnerability causes a use-after-free i ...)

1 affected package

rust-pyo3

Package 20.04 LTS
rust-pyo3 Not in release
Show less packages

CVE-2024-9823

Medium priority
Needs evaluation

(There exists a security vulnerability in Jetty's DosFilter which can b ...)

2 affected packages

jetty, jetty9

Package 20.04 LTS
jetty Not in release
jetty9 Needs evaluation
Show less packages

CVE-2024-9675

Medium priority

Not in release

(A vulnerability was found in Buildah. Cache mounts do not properly val ...)

1 affected package

golang-github-containers-buildah

Package 20.04 LTS
golang-github-containers-buildah Not in release
Show less packages