Search CVE reports


Toggle filters

921 – 930 of 56918 results

Status is adjusted based on your filters.


CVE-2026-77337

Medium priority
Needs evaluation

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and...

1 affected package

cakephp

Package 16.04 LTS
cakephp Needs evaluation
Show less packages

CVE-2026-68516

Medium priority
Needs evaluation

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal...

1 affected package

openexr

Package 16.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-77635

Medium priority
Needs evaluation

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled...

1 affected package

cakephp

Package 16.04 LTS
cakephp Needs evaluation
Show less packages

CVE-2026-77634

Medium priority
Needs evaluation

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not...

1 affected package

cakephp

Package 16.04 LTS
cakephp Needs evaluation
Show less packages

CVE-2026-77310

Medium priority
Needs evaluation

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines,...

1 affected package

jackson-databind

Package 16.04 LTS
jackson-databind Needs evaluation
Show less packages

CVE-2026-76816

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names...

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-76098

Medium priority
Needs evaluation

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk...

1 affected package

mistune

Package 16.04 LTS
mistune Needs evaluation
Show less packages

CVE-2026-71832

Medium priority
Needs evaluation

Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service

1 affected package

aria2

Package 16.04 LTS
aria2 Needs evaluation
Show less packages

CVE-2026-78475

Medium priority
Needs evaluation

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-78465

Medium priority
Needs evaluation

A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages