CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-22623 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... Not Provided 2022-03-18 2022-04-05
CVE-2022-22576 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 8.1 - HIGH 2022-05-26 2022-08-02
CVE-2021-22947 When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS securi... 5.9 - MEDIUM 2021-09-29 2022-08-02
CVE-2021-22946 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP ser... 7.5 - HIGH 2021-09-29 2022-08-02
CVE-2021-22945 When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to a... 9.1 - CRITICAL 2021-09-23 2022-08-02
CVE-2021-22926 libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT... 7.5 - HIGH 2021-08-05 2022-05-16
CVE-2021-22925 curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to se... 5.3 - MEDIUM 2021-08-05 2022-06-14
CVE-2021-22924 libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the s... 3.7 - LOW 2021-08-05 2022-08-02
CVE-2021-22923 When curl is instructed to get content using the metalink feature, and a user name and password are used to download the meta... 5.3 - MEDIUM 2021-08-05 2022-04-06
CVE-2021-22922 When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in th... 6.5 - MEDIUM 2021-08-05 2022-04-06
CVE-2021-22901 curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TL... 8.1 - HIGH 2021-06-11 2022-05-13
CVE-2021-22898 curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPT... 3.1 - LOW 2021-06-11 2022-08-02
CVE-2021-22897 curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SS... 5.3 - MEDIUM 2021-06-11 2022-05-13
CVE-2021-22890 curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to ba... 3.7 - LOW 2021-04-01 2022-04-06
CVE-2021-22876 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by... 5.3 - MEDIUM 2021-04-01 2022-04-06
CVE-2020-8286 curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of ... 7.5 - HIGH 2020-12-14 2022-05-13
CVE-2020-8285 curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard mat... 7.5 - HIGH 2020-12-14 2022-05-13
CVE-2020-8284 A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address ... 3.7 - LOW 2020-12-14 2022-05-13
CVE-2020-8231 Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. 7.5 - HIGH 2020-12-14 2022-05-13
CVE-2020-8177 curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too ove... 7.8 - HIGH 2020-12-14 2022-06-17

