Search CVE reports


Toggle filters

1441 – 1450 of 28288 results

Status is adjusted based on your filters.


CVE-2025-54121

Medium priority
Needs evaluation

Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater...

1 affected package

starlette

Package 24.04 LTS
starlette Needs evaluation
Show less packages

CVE-2025-7962

Medium priority
Needs evaluation

In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing theĀ \r and \n UTF-8 characters to separate different messages.

1 affected package

jakarta-mail

Package 24.04 LTS
jakarta-mail Needs evaluation
Show less packages

CVE-2025-30192

Medium priority
Needs evaluation

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled...

1 affected package

pdns-recursor

Package 24.04 LTS
pdns-recursor Needs evaluation
Show less packages

CVE-2025-50151

Medium priority
Needs evaluation

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not...

1 affected package

apache-jena

Package 24.04 LTS
apache-jena Needs evaluation
Show less packages

CVE-2025-49656

Medium priority
Needs evaluation

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.

1 affected package

apache-jena

Package 24.04 LTS
apache-jena Needs evaluation
Show less packages

CVE-2025-54352

Medium priority
Needs evaluation

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

1 affected package

wordpress

Package 24.04 LTS
wordpress Needs evaluation
Show less packages

CVE-2025-49087

Medium priority
Needs evaluation

In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.

1 affected package

mbedtls

Package 24.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2025-47917

Medium priority
Needs evaluation

Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is documented as...

1 affected package

mbedtls

Package 24.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2025-48965

Medium priority
Needs evaluation

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.

1 affected package

mbedtls

Package 24.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2025-54314

Medium priority
Needs evaluation

Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way...

1 affected package

ruby-thor

Package 24.04 LTS
ruby-thor Needs evaluation
Show less packages