Search CVE reports
1 – 10 of 28200 results
CVE-2024-45700
Medium priorityZabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and...
1 affected package
zabbix
Package | 22.04 LTS |
---|---|
zabbix | Needs evaluation |
CVE-2024-45699
Medium priorityThe endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output...
1 affected package
zabbix
Package | 22.04 LTS |
---|---|
zabbix | Needs evaluation |
CVE-2024-42325
Medium priorityZabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.
1 affected package
zabbix
Package | 22.04 LTS |
---|---|
zabbix | Needs evaluation |
CVE-2024-36469
Medium priorityExecution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.
1 affected package
zabbix
Package | 22.04 LTS |
---|---|
zabbix | Needs evaluation |
CVE-2024-36465
Medium priorityA low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
1 affected package
zabbix
Package | 22.04 LTS |
---|---|
zabbix | Needs evaluation |
CVE-2025-3085
Medium priorityNot in release
A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of...
1 affected package
mongodb
Package | 22.04 LTS |
---|---|
mongodb | Not in release |
CVE-2025-3084
Medium priorityNot in release
When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0...
1 affected package
mongodb
Package | 22.04 LTS |
---|---|
mongodb | Not in release |
CVE-2025-3083
Medium priorityNot in release
Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31, MongoDB...
1 affected package
mongodb
Package | 22.04 LTS |
---|---|
mongodb | Not in release |
CVE-2025-3082
Medium priorityNot in release
A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB...
1 affected package
mongodb
Package | 22.04 LTS |
---|---|
mongodb | Not in release |
CVE-2025-30673
Medium prioritySub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may...
1 affected package
libsub-handlesvia-perl
Package | 22.04 LTS |
---|---|
libsub-handlesvia-perl | Needs evaluation |