Search CVE reports
1 – 10 of 27965 results
CVE-2025-24814
Medium priorityCore creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are...
1 affected package
lucene-solr
Package | 20.04 LTS |
---|---|
lucene-solr | Needs evaluation |
CVE-2025-24359
Medium priorityASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute arbitrary Python code in the...
1 affected package
python-asteval
Package | 20.04 LTS |
---|---|
python-asteval | Needs evaluation |
CVE-2025-22620
Medium priorityNot in release
(gitoxide is an implementation of git written in Rust. Prior to 0.17.0, ...)
1 affected package
rust-gix-worktree-state
Package | 20.04 LTS |
---|---|
rust-gix-worktree-state | Not in release |
CVE-2025-22153
Medium priorityRestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Via a type confusion bug in versions of the CPython interpreter starting in 3.11...
1 affected package
restrictedpython
Package | 20.04 LTS |
---|---|
restrictedpython | Needs evaluation |
CVE-2025-21548
Medium priorityVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network...
1 affected package
mysql-connector-python
Package | 20.04 LTS |
---|---|
mysql-connector-python | Needs evaluation |
CVE-2025-0611
Medium priorityObject corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
1 affected package
chromium-browser
Package | 20.04 LTS |
---|---|
chromium-browser | Not affected |
CVE-2025-0314
Medium priorityNot in release
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.
1 affected package
gitlab
Package | 20.04 LTS |
---|---|
gitlab | Not in release |
CVE-2024-9979
Medium priorityNot in release
(A flaw was found in PyO3. This vulnerability causes a use-after-free i ...)
1 affected package
rust-pyo3
Package | 20.04 LTS |
---|---|
rust-pyo3 | Not in release |
CVE-2024-9823
Medium priority(There exists a security vulnerability in Jetty's DosFilter which can b ...)
2 affected packages
jetty, jetty9
Package | 20.04 LTS |
---|---|
jetty | Not in release |
jetty9 | Needs evaluation |
CVE-2024-9675
Medium priorityNot in release
(A vulnerability was found in Buildah. Cache mounts do not properly val ...)
1 affected package
golang-github-containers-buildah
Package | 20.04 LTS |
---|---|
golang-github-containers-buildah | Not in release |