Search CVE reports


Toggle filters

41 – 50 of 356 results


CVE-2024-21910

Medium priority
Needs evaluation

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-21908

Medium priority
Needs evaluation

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-46589

Medium priority

Some fixes available 8 of 13

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer...

6 affected packages

tomcat10, tomcat8, tomcat9, tomcat6, tomcat7, tomcat11

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat10 Not affected Not in release Not in release Ignored
tomcat8 Not in release Not in release Not in release Fixed
tomcat9 Fixed Fixed Fixed Fixed
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Ignored
tomcat11 Not in release Not in release Not in release Not in release
Show less packages

CVE-2023-48219

Medium priority
Needs evaluation

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-46853

Medium priority
Fixed

In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.

1 affected package

memcached

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
memcached Not affected Fixed Not affected Not affected
Show less packages

CVE-2023-46852

Medium priority
Fixed

In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.

1 affected package

memcached

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
memcached Not affected Fixed Not affected Not affected
Show less packages

CVE-2023-45819

Medium priority
Needs evaluation

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vulnerability exploits TinyMCE's unfiltered notification system, which is used in...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-45818

Medium priority
Needs evaluation

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-crafted HTML snippet passes the XSS sanitisation...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-45648

Medium priority

Some fixes available 8 of 13

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer...

6 affected packages

tomcat10, tomcat8, tomcat9, tomcat6, tomcat7, tomcat11

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat10 Not affected Not in release Not in release Ignored
tomcat8 Not in release Not in release Not in release Fixed
tomcat9 Fixed Fixed Fixed Fixed
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Ignored
tomcat11 Not in release Not in release Not in release Not in release
Show less packages

CVE-2023-42795

Medium priority

Some fixes available 8 of 13

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through...

6 affected packages

tomcat10, tomcat8, tomcat9, tomcat6, tomcat7, tomcat11

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat10 Not affected Not in release Not in release Ignored
tomcat8 Not in release Not in release Not in release Fixed
tomcat9 Fixed Fixed Fixed Fixed
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Ignored
tomcat11 Not in release Not in release Not in release Not in release
Show less packages