Search CVE reports


Toggle filters

1 – 10 of 52620 results

Status is adjusted based on your filters.


CVE-2025-49506

Medium priority
Needs evaluation

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on...

1 affected package

apr-util

Package 16.04 LTS
apr-util Needs evaluation
Show less packages

CVE-2026-15920

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with...

1 affected package

python-django

Package 16.04 LTS
python-django Needs evaluation
Show less packages

CVE-2026-15830

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects...

1 affected package

python-django

Package 16.04 LTS
python-django Needs evaluation
Show less packages

CVE-2026-15337

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which...

1 affected package

python-django

Package 16.04 LTS
python-django Needs evaluation
Show less packages

CVE-2026-15307

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor....

1 affected package

python-django

Package 16.04 LTS
python-django Needs evaluation
Show less packages

CVE-2026-18739

Medium priority
Needs evaluation

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal...

1 affected package

popt

Package 16.04 LTS
popt Needs evaluation
Show less packages

CVE-2026-13379

Medium priority
Needs evaluation

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

1 affected package

openvpn

Package 16.04 LTS
openvpn Needs evaluation
Show less packages

CVE-2026-17544

Medium priority
Needs evaluation

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5
php7.0 Needs evaluation
php7.2
php7.4
php8.1
php8.3
php8.5
Show all 7 packages Show less packages

CVE-2026-17543

Medium priority
Needs evaluation

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5
php7.0 Needs evaluation
php7.2
php7.4
php8.1
php8.3
php8.5
Show all 7 packages Show less packages

CVE-2026-16313

Medium priority
Needs evaluation

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a...

1 affected package

sg3-utils

Package 16.04 LTS
sg3-utils Needs evaluation
Show less packages