Search CVE reports


Toggle filters

241 – 250 of 47662 results

Status is adjusted based on your filters.


CVE-2026-26960

Medium priority
Needs evaluation

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction...

1 affected package

node-tar

Package 16.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2026-26065

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header variants) that...

1 affected package

calibre

Package 16.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-26064

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user has write...

1 affected package

calibre

Package 16.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-26967

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing...

1 affected package

pjproject

Package 16.04 LTS
pjproject Needs evaluation
Show less packages

CVE-2026-26203

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams...

1 affected package

pjproject

Package 16.04 LTS
pjproject Needs evaluation
Show less packages

CVE-2026-26200

Medium priority
Needs evaluation

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and...

1 affected package

hdf5

Package 16.04 LTS
hdf5 Needs evaluation
Show less packages

CVE-2026-27475

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27474

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27473

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27472

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages