CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result
389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue
Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read
Rubygem-katello: improper authorization logic allows resource enumeration
Rubygem-katello: sql injection in registry proxy via labels
Foreman: command injection in foreman-tail
Rubygem-hammer_cli: command injection via insecure editor invocation
Foreman: ssti and insecure deserialization in foreman-rake configuration
Foreman: command injection in foreman-rake database tasks
Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter
Foreman: unauthenticated information disclosure via provisioning token validation flaw
Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter
Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory
Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled
Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect
Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder
Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body
Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag
Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket
Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth
Libsoup: libsoup: heap buffer overflow during websocket client-frame masking
Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth
Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding
Kubevirt: kubevirt: virt-controller nil-pointer dereference via malformed ephemeral volume
Libsoup: libsoup: heap buffer overflow during websocket message reassembly
Showing 1 to 25 CVEs · page 1 (more available)