VendorsDebiandebian_linux11.0
Vulnerabilities

Debian Debian Linux 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2057CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Published 2025-03-10 · Analyzed
10.0KEV1 PoCEPSS 0.999
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
Published 2023-10-27 · Analyzed
10.0KEVEPSS 0.997
CVE-2022-0543
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
Published 2022-02-18 · Analyzed
10.0KEVEPSS 0.994
CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
Published 2025-04-16 · Analyzed
10.0KEVEPSS 0.988
CVE-2022-2068
The c_rehash script allows command injection
Published 2022-06-21 · Modified
10.0EPSS 0.954
CVE-2021-42392
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.
Published 2022-01-07 · Modified
10.0EPSS 0.832
CVE-2022-1292
The c_rehash script allows command injection
Published 2022-05-03 · Modified
10.0EPSS 0.826
CVE-2022-23221
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
Published 2022-01-19 · Modified
10.0EPSS 0.648
CVE-2021-38503
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Published 2021-12-08 · Modified
10.0EPSS 0.038
CVE-2025-24201
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
Published 2025-03-11 · Analyzed
10.0KEVEPSS 0.038
CVE-2021-40393
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-12-22 · Modified
10.0EPSS 0.031
CVE-2021-40394
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-12-22 · Modified
10.0EPSS 0.029
CVE-2022-24720
Improper Input Validation in image_processing
Published 2022-03-01 · Modified
10.0EPSS 0.027
CVE-2022-30123
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
Published 2022-12-05 · Modified
10.0EPSS 0.019
CVE-2021-40401
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-04 · Modified
10.0EPSS 0.013
CVE-2024-42472
Flatpak may allow access to files outside sandbox for certain apps
Published 2024-08-15 · Analyzed
10.0EPSS 0.013
CVE-2022-24884
Trivial signature forgery in ecdsautils
Published 2022-05-05 · Modified
10.0EPSS 0.010
CVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Published 2025-06-02 · Analyzed
9.9KEV1 PoCEPSS 0.989
CVE-2021-21345
XStream is vulnerable to a Remote Command Execution attack
Published 2021-03-22 · Analyzed
9.9EPSS 0.723
CVE-2025-0781
Incorrect Authorization in SimGear
Published 2025-01-28 · Analyzed
9.9EPSS 0.004
CVE-2023-27372
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
Published 2023-02-28 · Modified
9.81 PoCEPSS 0.997
CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Published 2026-01-21 · Analyzed
9.8KEV1 PoCEPSS 0.981
CVE-2021-44790
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
Published 2021-12-20 · Analyzed
9.81 PoCEPSS 0.968
CVE-2021-3711
SM2 Decryption Buffer Overflow
Published 2021-08-24 · Modified
9.8EPSS 0.878
CVE-2021-26120
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
Published 2021-02-22 · Modified
9.8EPSS 0.823
CVE-2021-21346
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.764
CVE-2021-21344
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.760
CVE-2021-25281
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.
Published 2021-02-27 · Modified
9.8EPSS 0.731
CVE-2021-3197
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
Published 2021-02-27 · Modified
9.8EPSS 0.723
CVE-2022-29155
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.
Published 2022-05-04 · Modified
9.8EPSS 0.645
CVE-2024-47175
libppd's ppdCreatePPDFromIPP2 function does not sanitize IPP attributes when creating the PPD buffer
Published 2024-09-26 · Modified
9.8EPSS 0.636
CVE-2022-33980
Apache Commons Configuration insecure interpolation defaults
Published 2022-07-06 · Modified
9.8EPSS 0.456
CVE-2025-68615
Net-SNMP snmptrapd crash
Published 2025-12-22 · Analyzed
9.8EPSS 0.424
CVE-2021-44026
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
Published 2021-11-19 · Analyzed
9.8KEVEPSS 0.419
CVE-2021-39275
ap_escape_quotes buffer overflow
Published 2021-09-16 · Analyzed
9.8EPSS 0.394
CVE-2022-25236
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
Published 2022-02-16 · Modified
9.8EPSS 0.359
CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
Published 2024-10-09 · Analyzed
9.8KEVEPSS 0.232
CVE-2025-37924
ksmbd: fix use-after-free in kerberos authentication
Published 2025-05-20 · Modified
9.8EPSS 0.212
CVE-2022-28346
An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.
Published 2022-04-12 · Modified
9.8EPSS 0.187
1 / 52Next →