Search CVE reports


Toggle filters

441 – 450 of 62088 results


CVE-2025-13699

Medium priority
Needs evaluation

[Unknown description]

1 affected package

mariadb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb Needs evaluation Not in release
Show less packages

CVE-2025-66433

Medium priority

HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed in 24.12.14, 25.0.3, and 25.3.1. The earliest affected version is 24.7.3.

0 affected package


CVE-2025-66424

Medium priority
Needs evaluation

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

1 affected package

tryton-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tryton-server Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-66423

Medium priority
Needs evaluation

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

1 affected package

tryton-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tryton-server Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-66422

Medium priority
Needs evaluation

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

1 affected package

tryton-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tryton-server Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-66421

Medium priority
Needs evaluation

Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.69.

1 affected package

tryton-sao

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tryton-sao Needs evaluation Not in release
Show less packages

CVE-2025-66420

Medium priority
Needs evaluation

Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and 6.0.67.

1 affected package

tryton-sao

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tryton-sao Needs evaluation Not in release
Show less packages

CVE-2025-66221

Medium priority
Not affected

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that...

1 affected package

python-werkzeug

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-werkzeug Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-66034

Medium priority
Fixed

fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script has an arbitrary file write vulnerability that leads to...

1 affected package

fonttools

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fonttools Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-12183

Medium priority
Needs evaluation

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

1 affected package

lz4-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation
Show less packages