Search CVE reports


Toggle filters

1 – 10 of 36556 results

Status is adjusted based on your filters.


CVE-2026-23745

Medium priority
Needs evaluation

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to...

1 affected package

node-tar

Package 20.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2026-23643

Medium priority
Needs evaluation

CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.

1 affected package

cakephp

Package 20.04 LTS
cakephp Needs evaluation
Show less packages

CVE-2026-23535

Medium priority
Needs evaluation

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.

1 affected package

wlc

Package 20.04 LTS
wlc Needs evaluation
Show less packages

CVE-2026-23490

Medium priority
Needs evaluation

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

1 affected package

pyasn1

Package 20.04 LTS
pyasn1 Needs evaluation
Show less packages

CVE-2026-22865

Medium priority
Needs evaluation

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...

1 affected package

gradle

Package 20.04 LTS
gradle Needs evaluation
Show less packages

CVE-2026-22816

Medium priority
Needs evaluation

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...

1 affected package

gradle

Package 20.04 LTS
gradle Needs evaluation
Show less packages

CVE-2026-21265

Medium priority
Not affected

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot...

3 affected packages

secureboot-db, shim-signed, shim

Package 20.04 LTS
secureboot-db Not affected
shim-signed Not affected
shim Not affected
Show less packages

CVE-2026-0897

Medium priority
Needs evaluation

(Allocation of Resources Without Limits or Throttling in the HDF5 weigh ...)

1 affected package

keras

Package 20.04 LTS
keras Needs evaluation
Show less packages

CVE-2025-15537

Medium priority
Needs evaluation

A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such manipulation leads to heap-based buffer overflow....

1 affected package

mapnik

Package 20.04 LTS
mapnik Needs evaluation
Show less packages

CVE-2025-15536

Medium priority
Needs evaluation

A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The...

1 affected package

opencc

Package 20.04 LTS
opencc Needs evaluation
Show less packages