Search CVE reports


Toggle filters

51 – 60 of 21693 results

Status is adjusted based on your filters.


CVE-2024-54152

Medium priority
Needs evaluation

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the...

1 affected package

angular.js

Package 24.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2024-55638

Medium priority

Not in release

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-55637

Medium priority

Not in release

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-55636

Medium priority

Not in release

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-55635

Medium priority

Not in release

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-55634

Medium priority

Not in release

A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-12393

Medium priority

Not in release

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0...

1 affected package

drupal7

Package 24.04 LTS
drupal7 Not in release
Show less packages

CVE-2024-55601

Medium priority
Needs evaluation

Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks. Those whoa re impacted are...

1 affected package

hugo

Package 24.04 LTS
hugo Needs evaluation
Show less packages

CVE-2024-55566

Medium priority
Needs evaluation

ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.

1 affected package

colpack

Package 24.04 LTS
colpack Needs evaluation
Show less packages

CVE-2024-55564

Medium priority
Needs evaluation

The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.

1 affected package

libposix-2008-perl

Package 24.04 LTS
libposix-2008-perl Needs evaluation
Show less packages