cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 22 of 264
CVE-2022-46341P3HIGHCVSS 8.8v36v372022-12-14
CVE-2022-46341 [HIGH] CWE-787 CVE-2022-46341: A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveU A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
nvd
CVE-2019-16942P3CRITICALCVSS 9.8v30v312019-10-01
CVE-2019-16942 [CRITICAL] CWE-502 CVE-2019-16942: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible
nvd
CVE-2019-10086P3HIGHCVSS 7.3v30v312019-08-20
CVE-2019-10086 [HIGH] CWE-502 CVE-2019-10086: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressi In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
nvd
CVE-2020-13777P3HIGHCVSS 7.4v31v322020-06-04
CVE-2020-13777 [HIGH] CWE-327 CVE-2020-13777: GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of co GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryp
nvd
CVE-2023-5540P3HIGHCVSS 8.8v382023-11-09
CVE-2023-5540 [HIGH] CWE-94 CVE-2023-5540: A remote code execution risk was identified in the IMSCP activity. By default this was only availabl A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
nvd
CVE-2023-5539P3HIGHCVSS 8.8v382023-11-09
CVE-2023-5539 [HIGH] CWE-94 CVE-2023-5539: A remote code execution risk was identified in the Lesson activity. By default this was only availab A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
nvd
CVE-2024-24549P3HIGHCVSS 7.5v39v402024-03-13
CVE-2024-24549 [HIGH] CWE-20 CVE-2024-24549: Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomca Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through
nvd
CVE-2022-37454P3CRITICALCVSS 9.8v35v362022-10-21
CVE-2022-37454 [CRITICAL] CWE-190 CVE-2022-37454: The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
nvd
CVE-2016-9013P3CRITICALCVSS 9.8v24v252016-12-09
CVE-2016-9013 [CRITICAL] CWE-798 CVE-2016-9013: Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password f Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dict
nvd
CVE-2020-28036P3CRITICALCVSS 9.8v31v32+1 more2020-11-02
CVE-2020-28036 [CRITICAL] CWE-862 CVE-2020-28036: wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
nvd
CVE-2023-39357P2HIGHCVSS 8.8v37v382023-09-05
CVE-2023-39357 [HIGH] CWE-20 CVE-2023-39357: Cacti is an open source operational monitoring and fault management framework. A defect in the sql_s Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the sql_save function do not perform prior validation of user input, leading to the existence of multiple S
nvd
CVE-2023-5002P2HIGHCVSS 8.8v37v382023-09-22
CVE-2023-5002 [HIGH] CWE-78 CVE-2023-5002: A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. Versions of pgAdmin prior to 7.6 failed to properly control the server code executed on this API, allowing an authenticated user to run arbitrary commands on the server.
nvd
CVE-2021-33829P3MEDIUMCVSS 6.1PoCv33v34+1 more2021-06-09
CVE-2021-33829 [MEDIUM] CWE-79 CVE-2021-33829: A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4 A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
nvd
CVE-2019-16943P3CRITICALCVSS 9.8v30v312019-10-01
CVE-2019-16943 [CRITICAL] CWE-502 CVE-2019-16943: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to m
nvd
CVE-2023-43655P2HIGHCVSS 8.8v37v382023-09-29
CVE-2023-43655 [HIGH] CWE-74 CVE-2023-43655: Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessibl Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised
nvd
CVE-2020-13753P3CRITICALCVSS 10.0v312020-07-14
CVE-2020-13753 [CRITICAL] CVE-2020-13753: The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling termi
nvd
CVE-2020-0452P2CRITICALCVSS 9.8v32v332020-11-10
CVE-2020-0452 [CRITICAL] CWE-190 CVE-2020-0452: In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer o In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1
nvd
CVE-2020-11988P3HIGHCVSS 8.2v33v342021-02-24
CVE-2020-11988 [HIGH] CWE-20 CVE-2020-11988: Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by i Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.
nvd
CVE-2015-4870P3MEDIUMCVSS 4.0PoCv232015-10-21
CVE-2015-4870 [MEDIUM] CVE-2015-4870: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
nvd
CVE-2014-8089P3CRITICALCVSS 9.8v19v20+1 more2020-02-17
CVE-2014-8089 [CRITICAL] CWE-89 CVE-2014-8089: SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2. SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
nvd
Fedoraproject Fedora vulnerabilities | cvebase