Search CVE reports


Toggle filters

3011 – 3020 of 39004 results

Status is adjusted based on your filters.


CVE-2025-22239

Medium priority
Needs evaluation

Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.

1 affected package

salt

Package 18.04 LTS
salt Needs evaluation
Show less packages

CVE-2025-22238

Medium priority
Needs evaluation

Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.

1 affected package

salt

Package 18.04 LTS
salt Needs evaluation
Show less packages

CVE-2025-22237

Medium priority
Needs evaluation

An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.

1 affected package

salt

Package 18.04 LTS
salt Needs evaluation
Show less packages

CVE-2025-22236

Medium priority
Needs evaluation

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

1 affected package

salt

Package 18.04 LTS
salt Needs evaluation
Show less packages

CVE-2024-38825

Medium priority
Needs evaluation

The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not...

1 affected package

salt

Package 18.04 LTS
salt Needs evaluation
Show less packages

CVE-2024-38823

Medium priority
Needs evaluation

Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.

1 affected package

salt

Package 18.04 LTS
salt Needs evaluation
Show less packages

CVE-2024-38822

Medium priority
Needs evaluation

Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another minion.

1 affected package

salt

Package 18.04 LTS
salt Needs evaluation
Show less packages

CVE-2025-41234

Medium priority
Needs evaluation

Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset,...

1 affected package

libspring-java

Package 18.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2025-49589

Medium priority
Needs evaluation

PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE function of PCSX2 versions up to 2.3.414. Opening a disc image that logs a specially crafted message may allow a...

1 affected package

pcsx2

Package 18.04 LTS
pcsx2 Needs evaluation
Show less packages

CVE-2024-44905

Medium priority
Needs evaluation

go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.

1 affected package

golang-gopkg-pg.v5

Package 18.04 LTS
golang-gopkg-pg.v5 Needs evaluation
Show less packages