Search CVE reports


Toggle filters

16181 – 16190 of 44107 results

Status is adjusted based on your filters.


CVE-2022-3866

Medium priority
Ignored

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.

1 affected package

nomad

Package 16.04 LTS
nomad Ignored
Show less packages

CVE-2022-39307

Medium priority
Vulnerable

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not...

1 affected package

grafana

Package 16.04 LTS
grafana Vulnerable
Show less packages

CVE-2022-3486

Medium priority
Ignored

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2022-3483

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2022-3285

Medium priority
Ignored

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2022-3280

Medium priority
Ignored

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2022-3265

Medium priority
Ignored

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2022-2761

Medium priority
Ignored

An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2022-41064

Medium priority
Ignored

.NET Framework Information Disclosure Vulnerability

1 affected package

dotnet6

Package 16.04 LTS
dotnet6 Ignored
Show less packages

CVE-2022-39306

Medium priority
Vulnerable

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they...

1 affected package

grafana

Package 16.04 LTS
grafana Vulnerable
Show less packages