Search CVE reports


Toggle filters

31 – 40 of 36612 results

Status is adjusted based on your filters.


CVE-2025-69644

Medium priority
Needs evaluation

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers...

1 affected package

binutils

Package 22.04 LTS
binutils Needs evaluation
Show less packages

CVE-2023-26486

Medium priority

Not in release

(Vega is a visualization grammar, a declarative format for creating, sa ...)

1 affected package

vega.js

Package 22.04 LTS
vega.js Not in release
Show less packages

CVE-2026-3606

Medium priority
Needs evaluation

A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads...

1 affected package

ettercap

Package 22.04 LTS
ettercap Needs evaluation
Show less packages

CVE-2026-29062

Medium priority
Needs evaluation

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing...

1 affected package

jackson-core

Package 22.04 LTS
jackson-core Needs evaluation
Show less packages

CVE-2026-28804

Medium priority

Not in release

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode...

1 affected package

pypdf

Package 22.04 LTS
pypdf Not in release
Show less packages

CVE-2026-28802

Medium priority
Needs evaluation

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the...

1 affected package

python-authlib

Package 22.04 LTS
python-authlib Needs evaluation
Show less packages

CVE-2026-28350

Medium priority

Not in release

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head,...

1 affected package

lxml-html-clean

Package 22.04 LTS
lxml-html-clean Not in release
Show less packages

CVE-2026-28348

Medium priority

Not in release

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes...

1 affected package

lxml-html-clean

Package 22.04 LTS
lxml-html-clean Not in release
Show less packages

CVE-2026-28343

Medium priority
Needs evaluation

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be...

4 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 22.04 LTS
ckeditor Needs evaluation
ckeditor3 Needs evaluation
ldap-account-manager Needs evaluation
request-tracker4 Needs evaluation
Show less packages

CVE-2026-0848

Medium priority
Needs evaluation

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An...

1 affected package

nltk

Package 22.04 LTS
nltk Needs evaluation
Show less packages