CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

fedoraproject

extra_packages_for_enterprise_linux

76 known vulnerabilities · sorted by CVSS score

CVE-2022-4170
CRITICAL9.8

The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.

rxvt-unicode_project / rxvt-unicode+3
Network
Published Dec 9, 2022
Page 1 of 4
CVE-2022-40315
CRITICAL9.8

A limited SQL injection risk was identified in the "browse list of users" site administration page.

moodle / moodle+5
Network
Published Sep 30, 2022
CVE-2023-34152
CRITICAL9.8

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

imagemagick / imagemagick+5
Network
Published May 30, 2023
CVE-2022-45152
CRITICAL9.1

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.

moodle / moodle+6
Network
Published Nov 25, 2022
CVE-2022-24882
CRITICAL9.1

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.

freerdp / freerdp+4
Network
Published Apr 26, 2022
CVE-2021-45079
CRITICAL9.1

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.

strongswan / strongswan+13
Network
Published Jan 31, 2022
CVE-2022-2296
HIGH8.8

Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions.

google / chrome+3
Network
Published Jul 28, 2022
CVE-2021-38714
HIGH8.8

In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

plib_project / plib+6
Network
Published Aug 24, 2021
CVE-2022-2158
HIGH8.8

Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+3
Network
Published Jul 28, 2022
CVE-2022-2294
HIGH8.8

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+30
Network
Published Jul 28, 2022
CVE-2022-0983
HIGH8.8

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

moodle / moodle+5
Network
Published Mar 25, 2022
CVE-2022-2295
HIGH8.8

Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+3
Network
Published Jul 28, 2022
CVE-2021-21897
HIGH8.8

A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

ribbonsoft / dxflib+6
Network
Published Sep 8, 2021
CVE-2021-43559
HIGH8.8

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

moodle / moodle+5
Network
Published Nov 22, 2021
CVE-2022-2163
HIGH8.8

Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction.

google / chrome+3
Network
Published Jul 28, 2022
CVE-2022-25648
HIGH8.1

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

git / git+5
Network
Published Apr 19, 2022
CVE-2023-34153
HIGH7.8

A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.

imagemagick / imagemagick+5
Local
Published May 30, 2023
CVE-2022-0367
HIGH7.8

A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.

libmodbus / libmodbus+3
Local
Published Aug 29, 2022
CVE-2022-32545
HIGH7.8

A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.

imagemagick / imagemagick+4
Local
Published Jun 16, 2022
CVE-2022-32546
HIGH7.8

A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.

imagemagick / imagemagick+5
Local
Published Jun 16, 2022