Search CVE reports


Toggle filters

1 – 10 of 34330 results

Status is adjusted based on your filters.


CVE-2025-65431

Medium priority
Needs evaluation

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for...

1 affected package

django-allauth

Package 22.04 LTS
django-allauth Needs evaluation
Show less packages

CVE-2025-65430

Medium priority
Needs evaluation

An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.

1 affected package

django-allauth

Package 22.04 LTS
django-allauth Needs evaluation
Show less packages

CVE-2025-37731

Medium priority

Not in release

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted...

1 affected package

elasticsearch

Package 22.04 LTS
elasticsearch Not in release
Show less packages

CVE-2025-14714

Medium priority
Not affected

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By...

1 affected package

libreoffice

Package 22.04 LTS
libreoffice Not affected
Show less packages

CVE-2025-13281

Medium priority
Not affected

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information...

1 affected package

kubernetes

Package 22.04 LTS
kubernetes Not affected
Show less packages

CVE-2025-9615

Medium priority
Vulnerable

[avoid that non-admin user using other users certificates]

1 affected package

network-manager

Package 22.04 LTS
network-manager Vulnerable
Show less packages

CVE-2025-67899

Medium priority
Needs evaluation

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

1 affected package

uriparser

Package 22.04 LTS
uriparser Needs evaluation
Show less packages

CVE-2025-67897

Medium priority
Needs evaluation

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or...

1 affected package

rust-sequoia-openpgp

Package 22.04 LTS
rust-sequoia-openpgp Needs evaluation
Show less packages

CVE-2025-67896

High priority
Not affected

Exim before 4.99.1 allows remote heap corruption that will be further described on 2025-12-18.

1 affected package

exim4

Package 22.04 LTS
exim4 Not affected
Show less packages

CVE-2025-67749

Medium priority
Needs evaluation

PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. In versions 2.5.377 and below, an unchecked offset and size used in a memcpy operation inside PCSX2's CDVD SCMD 0x91 and SCMD 0x8F handlers allow a specially crafted...

1 affected package

pcsx2

Package 22.04 LTS
pcsx2 Needs evaluation
Show less packages