Search CVE reports


Toggle filters

1 – 10 of 28400 results

Status is adjusted based on your filters.


CVE-2025-32387

Medium priority
Needs evaluation

Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack...

1 affected package

helm

Package 22.04 LTS
helm Needs evaluation
Show less packages

CVE-2025-32386

Medium priority
Needs evaluation

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart,...

1 affected package

helm

Package 22.04 LTS
helm Needs evaluation
Show less packages

CVE-2025-30215

Medium priority

Not in release

[Unknown description]

1 affected package

nats-server

Package 22.04 LTS
nats-server Not in release
Show less packages

CVE-2025-32464

Medium priority
Fixed

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

1 affected package

haproxy

Package 22.04 LTS
haproxy Fixed
Show less packages

CVE-2025-32460

Medium priority
Needs evaluation

GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

1 affected package

graphicsmagick

Package 22.04 LTS
graphicsmagick Needs evaluation
Show less packages

CVE-2025-31672

Medium priority
Needs evaluation

[Unknown description]

1 affected package

libapache-poi-java

Package 22.04 LTS
libapache-poi-java Needs evaluation
Show less packages

CVE-2025-31344

Medium priority
Needs evaluation

[Unknown description]

1 affected package

giflib

Package 22.04 LTS
giflib Needs evaluation
Show less packages

CVE-2025-22871

Medium priority
Needs evaluation

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare...

2 affected packages

golang-1.23, golang-1.24

Package 22.04 LTS
golang-1.23 Needs evaluation
golang-1.24 Not in release
Show less packages

CVE-2025-3416

Medium priority
Needs evaluation

A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to...

1 affected package

rust-openssl

Package 22.04 LTS
rust-openssl Needs evaluation
Show less packages

CVE-2025-26675

Medium priority
Needs evaluation

Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

1 affected package

wsl

Package 22.04 LTS
wsl Needs evaluation
Show less packages