Search CVE reports


Toggle filters

1491 – 1500 of 50613 results

Status is adjusted based on your filters.


CVE-2026-55584

Medium priority
Needs evaluation

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before...

1 affected package

phpsysinfo

Package 22.04 LTS
phpsysinfo Needs evaluation
Show less packages

CVE-2026-55520

Medium priority
Needs evaluation

Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Disallow directive into a lazy...

1 affected package

python-protego

Package 22.04 LTS
python-protego Needs evaluation
Show less packages

CVE-2026-82330

Medium priority
Needs evaluation

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap...

1 affected package

gimp

Package 22.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-82328

Medium priority
Needs evaluation

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory...

1 affected package

gimp

Package 22.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-82327

Medium priority
Needs evaluation

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id...

1 affected package

libsolv

Package 22.04 LTS
libsolv Needs evaluation
Show less packages

CVE-2026-82324

Medium priority
Needs evaluation

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color...

1 affected package

gimp

Package 22.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-75758

Medium priority

Not in release

Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM node's memory. Inspect.List's charlist...

1 affected package

elixir

Package 22.04 LTS
elixir Not in release
Show less packages

CVE-2026-56854

Medium priority
Needs evaluation

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions...

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 22.04 LTS
golang-go.crypto Needs evaluation
snapd Needs evaluation
lxd Not in release
google-guest-agent Needs evaluation
Show less packages

CVE-2026-37236

Medium priority
Needs evaluation

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type...

1 affected package

golang-github-grpc-ecosystem-grpc-gateway

Package 22.04 LTS
golang-github-grpc-ecosystem-grpc-gateway Needs evaluation
Show less packages

CVE-2026-15603

Medium priority
Needs evaluation

morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line...

1 affected package

node-morgan

Package 22.04 LTS
node-morgan Needs evaluation
Show less packages