Search CVE reports


Toggle filters

1 – 10 of 31440 results

Status is adjusted based on your filters.


CVE-2026-23745

Medium priority
Needs evaluation

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to...

1 affected package

node-tar

Package 24.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2026-23643

Medium priority

Not in release

CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.

1 affected package

cakephp

Package 24.04 LTS
cakephp Not in release
Show less packages

CVE-2026-23535

Medium priority
Needs evaluation

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.

1 affected package

wlc

Package 24.04 LTS
wlc Needs evaluation
Show less packages

CVE-2026-23490

Medium priority
Needs evaluation

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

1 affected package

pyasn1

Package 24.04 LTS
pyasn1 Needs evaluation
Show less packages

CVE-2026-22865

Medium priority
Needs evaluation

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...

1 affected package

gradle

Package 24.04 LTS
gradle Needs evaluation
Show less packages

CVE-2026-22816

Medium priority
Needs evaluation

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...

1 affected package

gradle

Package 24.04 LTS
gradle Needs evaluation
Show less packages

CVE-2026-21265

Medium priority
Not affected

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot...

3 affected packages

secureboot-db, shim-signed, shim

Package 24.04 LTS
secureboot-db Not affected
shim-signed Not affected
shim Not affected
Show less packages

CVE-2026-1144

Medium priority
Needs evaluation

A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed...

1 affected package

quickjs

Package 24.04 LTS
quickjs Needs evaluation
Show less packages

CVE-2026-0943

Medium priority

Not in release

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball,...

1 affected package

libharfbuzz-shaper-perl

Package 24.04 LTS
libharfbuzz-shaper-perl Not in release
Show less packages

CVE-2026-0897

Medium priority

Not in release

(Allocation of Resources Without Limits or Throttling in the HDF5 weigh ...)

1 affected package

keras

Package 24.04 LTS
keras Not in release
Show less packages