Search CVE reports


Toggle filters

51 – 60 of 32446 results

Status is adjusted based on your filters.


CVE-2026-22206

Medium priority
Needs evaluation

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL...

1 affected package

spip

Package 24.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-22205

Medium priority
Needs evaluation

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in...

1 affected package

spip

Package 24.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27141

Medium priority
Needs evaluation

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS
golang-golang-x-net Needs evaluation
google-guest-agent Needs evaluation
containerd Needs evaluation
golang-golang-x-net-dev Not in release
adsys Needs evaluation
juju-core Not in release
lxd Not in release
Show all 7 packages Show less packages

CVE-2026-28296

Medium priority
Needs evaluation

A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized...

1 affected package

gvfs

Package 24.04 LTS
gvfs Needs evaluation
Show less packages

CVE-2026-28295

Medium priority
Needs evaluation

A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information...

1 affected package

gvfs

Package 24.04 LTS
gvfs Needs evaluation
Show less packages

CVE-2025-64999

Medium priority

Not in release

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into the Synthetic Monitoring HTML...

1 affected package

check-mk

Package 24.04 LTS
check-mk Not in release
Show less packages

CVE-2026-27970

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability...

1 affected package

angular.js

Package 24.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2026-27942

Medium priority
Needs evaluation

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML...

1 affected package

node-webfont

Package 24.04 LTS
node-webfont Needs evaluation
Show less packages

CVE-2026-3184

Medium priority
Needs evaluation

[Access control bypass due to improper hostname canonicalization]

1 affected package

util-linux

Package 24.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-27904

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with...

1 affected package

node-minimatch

Package 24.04 LTS
node-minimatch Needs evaluation
Show less packages