Search CVE reports
21 – 30 of 42038 results
Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or...
1 affected package
anki
| Package | 24.04 LTS |
|---|---|
| anki | Needs evaluation |
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow flag values without...
1 affected package
gh
| Package | 24.04 LTS |
|---|---|
| gh | Needs evaluation |
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content...
1 affected package
gh
| Package | 24.04 LTS |
|---|---|
| gh | Needs evaluation |
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or...
1 affected package
gh
| Package | 24.04 LTS |
|---|---|
| gh | Needs evaluation |
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As...
1 affected package
gh
| Package | 24.04 LTS |
|---|---|
| gh | Needs evaluation |
[Unknown description]
1 affected package
wordpress
| Package | 24.04 LTS |
|---|---|
| wordpress | Needs evaluation |
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...
2 affected packages
markdown, python-markdown
| Package | 24.04 LTS |
|---|---|
| markdown | Needs evaluation |
| python-markdown | Needs evaluation |
[Unknown description]
1 affected package
libvirt
| Package | 24.04 LTS |
|---|---|
| libvirt | Needs evaluation |
[A crafted DNS packet can cause increased memory and CPU consumption]
3 affected packages
dnsdist, pdns, pdns-recursor
| Package | 24.04 LTS |
|---|---|
| dnsdist | Needs evaluation |
| pdns | Needs evaluation |
| pdns-recursor | Needs evaluation |
Not in release
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated...
1 affected package
node-mermaid
| Package | 24.04 LTS |
|---|---|
| node-mermaid | Not in release |