Search CVE reports


Toggle filters

31 – 40 of 24339 results

Status is adjusted based on your filters.


CVE-2024-45700

Medium priority

Not in release

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and...

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2024-45699

Medium priority

Not in release

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output...

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2024-42325

Medium priority

Not in release

Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2024-36469

Medium priority

Not in release

Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2024-36465

Medium priority

Not in release

A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2025-3074

Medium priority
Not affected

Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-3073

Medium priority
Not affected

Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security...

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-3072

Medium priority
Not affected

Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium...

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-3071

Medium priority
Not affected

Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium...

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2025-3070

Medium priority
Not affected

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages