Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 234 of 264
CVE-2023-21962P4MEDIUMCVSS 4.9v37v38+1 more2023-04-18
CVE-2023-21962 [MEDIUM] CVE-2023-21962: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2023-21955P4MEDIUMCVSS 4.9v37v38+1 more2023-04-18
CVE-2023-21955 [MEDIUM] CVE-2023-21955: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2023-21933P4MEDIUMCVSS 4.9v37v38+1 more2023-04-18
CVE-2023-21933 [MEDIUM] CVE-2023-21933: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versi
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to ca
nvd
CVE-2023-21945P4MEDIUMCVSS 4.9v37v38+1 more2023-04-18
CVE-2023-21945 [MEDIUM] CVE-2023-21945: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2023-21935P4MEDIUMCVSS 4.9v37v38+1 more2023-04-18
CVE-2023-21935 [MEDIUM] CVE-2023-21935: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2023-22054P4MEDIUMCVSS 4.9v37v38+1 more2023-07-18
CVE-2023-22054 [MEDIUM] CVE-2023-22054: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2023-22057P4MEDIUMCVSS 4.9v37v38+1 more2023-07-18
CVE-2023-22057 [MEDIUM] CVE-2023-22057: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Support
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2023-21911P4MEDIUMCVSS 4.9v37v38+1 more2023-04-18
CVE-2023-21911 [MEDIUM] CVE-2023-21911: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2023-22046P4MEDIUMCVSS 4.9v37v38+1 more2023-07-18
CVE-2023-22046 [MEDIUM] CVE-2023-22046: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2023-22008P4MEDIUMCVSS 4.9v37v38+1 more2023-07-18
CVE-2023-22008 [MEDIUM] CVE-2023-22008: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2020-29562P4MEDIUMCVSS 4.8v322020-12-04
CVE-2020-29562 [MEDIUM] CWE-617 CVE-2020-29562: The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text
The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
nvd
CVE-2015-4826P4MEDIUMCVSS 4.0v232015-10-21
CVE-2015-4826 [MEDIUM] CVE-2015-4826: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Types.
nvd
CVE-2013-1812P4MEDIUMCVSS 4.3v17v182013-12-12
CVE-2013-1812 [MEDIUM] CWE-399 CVE-2013-1812: The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of servic
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
nvd
CVE-2023-39366P4MEDIUMCVSS 4.8v37v382023-09-05
CVE-2023-39366 [MEDIUM] CWE-79 CVE-2023-39366: Cacti is an open source operational monitoring and fault management framework. Affected versions are
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser
nvd
CVE-2020-28200P4MEDIUMCVSS 4.3v33v342021-06-28
CVE-2020-28200 [MEDIUM] CWE-770 CVE-2020-28200: The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
nvd
CVE-2023-39510P4MEDIUMCVSS 4.8v37v382023-09-05
CVE-2023-39510 [MEDIUM] CWE-79 CVE-2023-39510: Cacti is an open source operational monitoring and fault management framework. Affected versions are
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser
nvd
CVE-2023-39511P4MEDIUMCVSS 4.8v37v382023-09-06
CVE-2023-39511 [MEDIUM] CWE-79 CVE-2023-39511: Cacti is an open source operational monitoring and fault management framework. Affected versions are
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's b
nvd
CVE-2020-6442P4MEDIUMCVSS 4.3v30v31+1 more2020-04-13
CVE-2020-6442 [MEDIUM] CWE-668 CVE-2020-6442: Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attack
Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2024-29894P4MEDIUMCVSS 4.7v392024-05-14
CVE-2024-29894 [MEDIUM] CVE-2024-29894: Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others). However, it still generates the code out o
nvd
CVE-2020-6396P4MEDIUMCVSS 4.3v30v312020-02-11
CVE-2020-6396 [MEDIUM] CVE-2020-6396: Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacke
Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd