Search CVE reports


Toggle filters

251 – 260 of 37447 results

Status is adjusted based on your filters.


CVE-2026-27205

Low priority
Vulnerable

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache...

1 affected package

flask

Package 20.04 LTS
flask Vulnerable
Show less packages

CVE-2026-27199

Medium priority
Not affected

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previously reported...

1 affected package

python-werkzeug

Package 20.04 LTS
python-werkzeug Not affected
Show less packages

CVE-2026-2048

Medium priority
Needs evaluation

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-2047

Medium priority
Needs evaluation

GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-2045

Medium priority
Needs evaluation

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-2044

Medium priority
Needs evaluation

GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 20.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-27113

Medium priority
Needs evaluation

Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and prior to commit a4f6b8d8c90b3eaa33d13dfd1093062ab9c4b30c on the master branch, arbitrary command injection can...

1 affected package

liquidprompt

Package 20.04 LTS
liquidprompt Needs evaluation
Show less packages

CVE-2026-27026

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a malformed /FlateDecode stream, where the byte-by-byte...

2 affected packages

pypdf, pypdf2

Package 20.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-27025

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the /ToUnicode entry...

2 affected packages

pypdf, pypdf2

Package 20.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-27024

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the children of a TreeObject, for example as...

2 affected packages

pypdf, pypdf2

Package 20.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages