Search CVE reports


Toggle filters

1 – 10 of 28200 results

Status is adjusted based on your filters.


CVE-2024-45700

Medium priority
Needs evaluation

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and...

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2024-45699

Medium priority
Needs evaluation

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output...

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2024-42325

Medium priority
Needs evaluation

Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2024-36469

Medium priority
Needs evaluation

Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2024-36465

Medium priority
Needs evaluation

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

1 affected package

zabbix

Package 22.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2025-3085

Medium priority

Not in release

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2025-3084

Medium priority

Not in release

When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2025-3083

Medium priority

Not in release

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2025-3082

Medium priority

Not in release

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2025-30673

Medium priority
Needs evaluation

Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may...

1 affected package

libsub-handlesvia-perl

Package 22.04 LTS
libsub-handlesvia-perl Needs evaluation
Show less packages