Search CVE reports


Toggle filters

3461 – 3470 of 60258 results


CVE-2025-3634

Medium priority
Needs evaluation

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they...

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2025-43859

Medium priority
Fixed

h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This...

1 affected package

python-h11

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-h11 Fixed Not affected Not affected
Show less packages

CVE-2025-46421

Medium priority
Fixed

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to...

2 affected packages

libsoup3, libsoup2.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup3 Fixed Fixed Not in release
libsoup2.4 Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-46420

Medium priority
Fixed

A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Fixed Fixed Fixed Fixed
libsoup3 Fixed Fixed Not in release
Show less packages

CVE-2025-27820

Medium priority
Needs evaluation

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

1 affected package

httpcomponents-client

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
httpcomponents-client Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-1908

Medium priority
Ignored

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5,...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2025-0639

Medium priority
Ignored

An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2024-12244

Medium priority
Ignored

An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2025-46400

Medium priority
Not affected

In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.

1 affected package

fig2dev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fig2dev Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-46399

Medium priority
Not affected

A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.

1 affected package

fig2dev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fig2dev Not affected Not affected Not affected Not affected
Show less packages