Search CVE reports


Toggle filters

21 – 30 of 41740 results

Status is adjusted based on your filters.


CVE-2026-2913

Medium priority
Needs evaluation

A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffer overflow. It is possible to...

1 affected package

vips

Package 18.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-2903

Low priority
Needs evaluation

A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src/parse/ast.cc. This manipulation causes null pointer dereference. The attack can only be executed locally. The...

1 affected package

re2c

Package 18.04 LTS
re2c Needs evaluation
Show less packages

CVE-2026-2739

Medium priority
Needs evaluation

This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.

1 affected package

node-bn.js

Package 18.04 LTS
node-bn.js Needs evaluation
Show less packages

CVE-2026-27205

Low priority
Needs evaluation

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache...

1 affected package

flask

Package 18.04 LTS
flask Needs evaluation
Show less packages

CVE-2026-27199

Medium priority
Not affected

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previously reported...

1 affected package

python-werkzeug

Package 18.04 LTS
python-werkzeug Not affected
Show less packages

CVE-2026-27113

Medium priority
Needs evaluation

Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and prior to commit a4f6b8d8c90b3eaa33d13dfd1093062ab9c4b30c on the master branch, arbitrary command injection can...

1 affected package

liquidprompt

Package 18.04 LTS
liquidprompt Needs evaluation
Show less packages

CVE-2026-2708

Medium priority
Needs evaluation

[libsoup: HTTP/1 request smuggling primitives accepted (CL.CL and TE+CL) in soup_headers_parse()]

2 affected packages

libsoup2.4, libsoup3

Package 18.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2026-27026

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a malformed /FlateDecode stream, where the byte-by-byte...

2 affected packages

pypdf, pypdf2

Package 18.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-27025

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the /ToUnicode entry...

2 affected packages

pypdf, pypdf2

Package 18.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-27024

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the children of a TreeObject, for example as...

2 affected packages

pypdf, pypdf2

Package 18.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages