Search CVE reports


Toggle filters

241 – 250 of 32595 results

Status is adjusted based on your filters.


CVE-2025-3525

Medium priority

Not in release

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2025-14103

Medium priority

Not in release

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2026-3203

Medium priority
Needs evaluation

RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-3202

Medium priority
Needs evaluation

NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-3201

Medium priority
Needs evaluation

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

1 affected package

wireshark

Package 24.04 LTS
wireshark Needs evaluation
Show less packages

CVE-2026-27699

Medium priority
Needs evaluation

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames...

1 affected package

node-proxy-agents

Package 24.04 LTS
node-proxy-agents Needs evaluation
Show less packages

CVE-2026-21725

Medium priority

Not in release

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must...

1 affected package

grafana

Package 24.04 LTS
grafana Not in release
Show less packages

CVE-2026-26104

Medium priority
Not affected

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting...

1 affected package

udisks2

Package 24.04 LTS
udisks2 Not affected
Show less packages

CVE-2026-26103

Medium priority
Not affected

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the...

1 affected package

udisks2

Package 24.04 LTS
udisks2 Not affected
Show less packages

CVE-2025-11563

Medium priority
Not affected

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

1 affected package

curl

Package 24.04 LTS
curl Not affected
Show less packages