Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 196 of 264
CVE-2021-30539P4MEDIUMCVSS 5.4v33v342021-06-07
CVE-2021-30539 [MEDIUM] CWE-863 CVE-2021-30539: Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 al
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2021-20280P4MEDIUMCVSS 5.4v32v33+1 more2021-03-15
CVE-2021-20280 [MEDIUM] CWE-79 CVE-2021-20280: Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risk
Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
nvd
CVE-2021-41164P4MEDIUMCVSS 5.4v36v372021-11-17
CVE-2021-41164 [MEDIUM] CWE-79 CVE-2021-41164: CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been disco
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users us
nvd
CVE-2022-24728P4MEDIUMCVSS 5.4v36v372022-03-16
CVE-2022-24728 [MEDIUM] CWE-79 CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been disco
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. T
nvd
CVE-2023-5546P4MEDIUMCVSS 5.4v37v38+1 more2023-11-09
CVE-2023-5546 [MEDIUM] CWE-79 CVE-2023-5546: ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored X
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
nvd
CVE-2021-20282P4MEDIUMCVSS 5.3v32v342021-03-15
CVE-2021-20282 [MEDIUM] CWE-863 CVE-2021-20282: When creating a user account, it was possible to verify the account without having access to the ver
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
nvd
CVE-2022-30597P4MEDIUMCVSS 5.3v34v35+1 more2022-05-18
CVE-2022-30597 [MEDIUM] CWE-472 CVE-2022-30597: A flaw was found in moodle where the description user field was not hidden when being set as a hidde
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
nvd
CVE-2020-36241P4MEDIUMCVSS 5.5v342021-02-05
CVE-2020-36241 [MEDIUM] CWE-22 CVE-2020-36241: autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
nvd
CVE-2023-46219P4MEDIUMCVSS 5.3v382023-12-12
CVE-2023-46219 [MEDIUM] CWE-311 CVE-2023-46219: When saving HSTS data to an excessively long file name, curl could end up removing all contents, mak
When saving HSTS data to an excessively long file name, curl could end up
removing all contents, making subsequent requests using that file unaware of
the HSTS status they should otherwise use.
nvd
CVE-2022-46149P4MEDIUMCVSS 5.4v36v372022-11-30
CVE-2022-46149 [MEDIUM] CWE-125 CVE-2022-46149: Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior t
Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementation prior to 0.13.7, 0.14.11, and 0.15.2 are vulnerable to out-of-bounds read due to logic error handling list-of-list. This issue may lead someone to rem
nvd
CVE-2022-30596P4MEDIUMCVSS 5.4v34v35+1 more2022-05-18
CVE-2022-30596 [MEDIUM] CWE-79 CVE-2022-30596: A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments re
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
nvd
CVE-2024-31443P4MEDIUMCVSS 5.4v392024-05-14
CVE-2024-31443 [MEDIUM] CWE-79 CVE-2024-31443: Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of th
Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 c
nvd
CVE-2021-36568P4MEDIUMCVSS 5.4v35v362022-09-13
CVE-2021-36568 [MEDIUM] CWE-79 CVE-2021-36568: In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a r
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects Moodle 3.11 and Moodle 3.10.4 and Moodle 3.9.7.
nvd
CVE-2023-39513P4MEDIUMCVSS 5.4v37v382023-09-05
CVE-2023-39513 [MEDIUM] CWE-79 CVE-2023-39513: Cacti is an open source operational monitoring and fault management framework. Affected versions are
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's b
nvd
CVE-2021-29157P4MEDIUMCVSS 5.5v33v342021-06-28
CVE-2021-29157 [MEDIUM] CWE-22 CVE-2021-29157: Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
nvd
CVE-2022-45151P4MEDIUMCVSS 5.4v35v36+1 more2022-11-23
CVE-2022-45151 [MEDIUM] CWE-79 CVE-2022-45151: The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
nvd
CVE-2022-3201P4MEDIUMCVSS 5.4v372022-09-26
CVE-2022-3201 [MEDIUM] CWE-20 CVE-2022-3201: Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3431P4MEDIUMCVSS 5.3v392023-06-27
CVE-2023-3431 [MEDIUM] CWE-284 CVE-2023-3431: Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
nvd
CVE-2021-3447P4MEDIUMCVSS 5.5v32v33+1 more2021-04-01
CVE-2021-3447 [MEDIUM] CWE-532 CVE-2021-3447: A flaw was found in several ansible modules, where parameters containing credentials, such as secret
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters were not protected by the no_log feature. An attacker can take advantage of this information to steal th
nvd
CVE-2023-4194P4MEDIUMCVSS 5.5v37v382023-08-07
CVE-2023-4194 [MEDIUM] CVE-2023-4194: A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following upstream commits - a096ccca6e50 ("tun: tun_chr_open(): correctly initialize socket u
nvd