Search CVE reports
1441 – 1450 of 44020 results
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based...
1 affected package
mkdocs-material
| Package | 24.04 LTS |
|---|---|
| mkdocs-material | Needs evaluation |
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization,...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original...
1 affected package
binutils
| Package | 24.04 LTS |
|---|---|
| binutils | Needs evaluation |
Not in release
An authenticated user may view private Puppet module metadata without repository read access.
1 affected package
puppet
| Package | 24.04 LTS |
|---|---|
| puppet | Not in release |
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation...
1 affected package
389-ds-base
| Package | 24.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to...
1 affected package
libnet-cidr-set-perl
| Package | 24.04 LTS |
|---|---|
| libnet-cidr-set-perl | Needs evaluation |