Known Vulnerabilities for Directory Server by Fedora
Listed below are 3 of the newest known vulnerabilities associated with "Directory Server" by "Fedora".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103474 json | yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated man... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-102990 json | basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server ... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-102811 json | Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-100716 json | Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to v... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-100669 json | Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In we... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100372 json | ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticate... | Not Provided | 2026-09-25 | 2026-09-29 |
| CVE-2026-97554 json | In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid using uninitialized SIDs in cifs_posi... | Not Provided | 2026-09-25 | 2026-09-28 |
| CVE-2026-96538 json | WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in serve... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-95701 json | In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path compone... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-94383 json | The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extensio... | Not Provided | 2026-09-21 | 2026-09-21 |