cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 236 of 264
CVE-2021-30156P4MEDIUMCVSS 4.3v33v342021-04-09
CVE-2021-30156 [MEDIUM] CWE-200 CVE-2021-30156: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.
nvd
CVE-2021-30532P4MEDIUMCVSS 4.3v33v342021-06-07
CVE-2021-30532 [MEDIUM] CVE-2021-30532: Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 al Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2019-13757P4MEDIUMCVSS 4.3v30v312019-12-10
CVE-2019-13757 [MEDIUM] CVE-2019-13757: Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2021-21186P4MEDIUMCVSS 4.3v32v33+1 more2021-03-09
CVE-2021-21186 [MEDIUM] CWE-863 CVE-2021-21186: Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code.
nvd
CVE-2022-0112P4MEDIUMCVSS 4.3v34v35+1 more2022-02-12
CVE-2022-0112 [MEDIUM] CVE-2022-0112: Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.
nvd
CVE-2022-30598P4MEDIUMCVSS 4.3v34v35+1 more2022-05-18
CVE-2022-30598 [MEDIUM] CWE-200 CVE-2022-30598: A flaw was found in moodle where global search results could include author information on some acti A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.
nvd
CVE-2021-20283P4MEDIUMCVSS 4.3v32v342021-03-15
CVE-2021-20283 [MEDIUM] CWE-863 CVE-2021-20283: The web service responsible for fetching other users' enrolled courses did not validate that the req The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
nvd
CVE-2020-13230P4MEDIUMCVSS 4.3v31v322020-05-20
CVE-2020-13230 [MEDIUM] CWE-281 CVE-2020-13230: In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions gra In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).
nvd
CVE-2023-5850P4MEDIUMCVSS 4.3v37v38+1 more2023-11-01
CVE-2023-5850 [MEDIUM] CVE-2023-5850: Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacke Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
nvd
CVE-2011-4930P4MEDIUMCVSS 4.4v15v162014-02-10
CVE-2011-4930 [MEDIUM] CWE-134 CVE-2011-4930: Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x ver Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hol
nvd
CVE-2008-1375P4MEDIUMCVSS 6.9v82008-05-02
CVE-2008-1375 [MEDIUM] CWE-362 CVE-2008-1375: Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24 Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.
nvd
CVE-2023-2468P4MEDIUMCVSS 4.3v36v37+1 more2023-05-03
CVE-2023-2468 [MEDIUM] CVE-2023-2468: Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a r Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-3845P4MEDIUMCVSS 4.3v38v39+1 more2024-04-17
CVE-2024-3845 [MEDIUM] CWE-358 CVE-2024-3845: Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote at Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-30260P4MEDIUMCVSS 4.3v38v39+1 more2024-04-04
CVE-2024-30260 [MEDIUM] CWE-285 CVE-2024-30260: Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Pro Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
nvd
CVE-2023-4901P4MEDIUMCVSS 4.3v37v392023-09-12
CVE-2023-4901 [MEDIUM] CVE-2023-4901: Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4905P4MEDIUMCVSS 4.3v37v38+1 more2023-09-12
CVE-2023-4905 [MEDIUM] CVE-2023-4905: Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4902P4MEDIUMCVSS 4.3v37v38+1 more2023-09-12
CVE-2023-4902 [MEDIUM] CVE-2023-4902: Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attac Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-42453P4MEDIUMCVSS 4.3v37v382023-09-27
CVE-2023-42453 [MEDIUM] CWE-285 CVE-2023-42453: Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Use Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but simply mark it as read. This could be confusing as clients will show the event as read by the user, ev
nvd
CVE-2023-4906P4MEDIUMCVSS 4.3v37v38+1 more2023-09-12
CVE-2023-4906 [MEDIUM] CVE-2023-4906: Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4904P4MEDIUMCVSS 4.3v37v38+1 more2023-09-12
CVE-2023-4904 [MEDIUM] CVE-2023-4904: Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remot Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)
nvd
Fedoraproject Fedora vulnerabilities | cvebase