Search CVE reports


Toggle filters

1731 – 1740 of 60355 results


CVE-2025-34104

Medium priority
Not affected

An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and...

1 affected package

matomo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matomo Not in release Not in release
Show less packages

CVE-2025-6965

Medium priority

Some fixes available 7 of 12

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2...

2 affected packages

sqlite3, sqlite

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sqlite3 Fixed Fixed Fixed Fixed
sqlite Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-53819

Medium priority
Not affected

Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was applied to Nix 2.30.1. No known workarounds are available.

1 affected package

nix

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nix Not affected Not affected
Show less packages

CVE-2025-53643

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request....

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-53101

Medium priority

Some fixes available 6 of 7

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format...

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-53019

Medium priority

Some fixes available 5 of 6

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format...

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-53015

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-53014

Medium priority

Some fixes available 6 of 7

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an...

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-7519

Low priority
Needs evaluation

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution...

1 affected package

policykit-1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
policykit-1 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-53689

Medium priority
Needs evaluation

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8),...

1 affected package

jackrabbit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackrabbit Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages