Search CVE reports


Toggle filters

3131 – 3140 of 39618 results

Status is adjusted based on your filters.


CVE-2025-55130

Medium priority
Needs evaluation

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the...

1 affected package

nodejs

Package 20.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2025-56005

Medium priority
Ignored

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized...

1 affected package

ply

Package 20.04 LTS
ply Ignored
Show less packages

CVE-2025-33231

Medium priority
Needs evaluation

NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled search path element by exploiting insecure DLL search paths. A successful exploit...

1 affected package

nvidia-cuda-toolkit

Package 20.04 LTS
nvidia-cuda-toolkit Needs evaluation
Show less packages

CVE-2025-33230

Medium priority
Needs evaluation

NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this...

1 affected package

nvidia-cuda-toolkit

Package 20.04 LTS
nvidia-cuda-toolkit Needs evaluation
Show less packages

CVE-2025-33229

Medium priority
Needs evaluation

NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileges as the NVIDIA Nsight Visual Studio Edition Monitor application. A successful...

1 affected package

nvidia-cuda-toolkit

Package 20.04 LTS
nvidia-cuda-toolkit Needs evaluation
Show less packages

CVE-2025-33228

Medium priority
Needs evaluation

NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked...

1 affected package

nvidia-cuda-toolkit

Package 20.04 LTS
nvidia-cuda-toolkit Needs evaluation
Show less packages

CVE-2025-15281

Medium priority
Fixed

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree...

2 affected packages

glibc, eglibc

Package 20.04 LTS
glibc Fixed
eglibc
Show less packages

CVE-2026-23950

Medium priority
Needs evaluation

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive...

1 affected package

node-tar

Package 20.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2026-23876

Medium priority
Fixed

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Fixed
Show less packages

CVE-2026-23874

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages