Search CVE reports


Toggle filters

3071 – 3080 of 29434 results

Status is adjusted based on your filters.


CVE-2025-6709

Medium priority

Not in release

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious...

1 affected package

mongodb

Package 24.04 LTS
mongodb Not in release
Show less packages

CVE-2025-6707

Medium priority

Not in release

Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administrator. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB...

1 affected package

mongodb

Package 24.04 LTS
mongodb Not in release
Show less packages

CVE-2025-6706

Medium priority

Not in release

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected...

1 affected package

mongodb

Package 24.04 LTS
mongodb Not in release
Show less packages

CVE-2025-5846

Medium priority

Not in release

An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign unrelated compliance frameworks...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2025-5315

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2025-3279

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2025-2938

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2025-1754

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2024-6174

Medium priority
Fixed

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

1 affected package

cloud-init

Package 24.04 LTS
cloud-init Fixed
Show less packages

CVE-2024-11584

Medium priority
Fixed

cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An...

1 affected package

cloud-init

Package 24.04 LTS
cloud-init Fixed
Show less packages