Search CVE reports


Toggle filters

331 – 340 of 46143 results

Status is adjusted based on your filters.


CVE-2026-53500

Medium priority

Not in release

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the...

1 affected package

thumbor

Package 22.04 LTS
thumbor Not in release
Show less packages

CVE-2026-18321

Medium priority
Needs evaluation

Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd

1 affected package

ntpsec

Package 22.04 LTS
ntpsec Needs evaluation
Show less packages

CVE-2026-54707

Medium priority
Needs evaluation

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive...

1 affected package

onionshare

Package 22.04 LTS
onionshare Needs evaluation
Show less packages

CVE-2026-54706

Medium priority
Needs evaluation

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links...

1 affected package

onionshare

Package 22.04 LTS
onionshare Needs evaluation
Show less packages

CVE-2026-18446

Medium priority
Needs evaluation

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or...

1 affected package

node-ajv

Package 22.04 LTS
node-ajv Needs evaluation
Show less packages

CVE-2026-18358

Medium priority
Needs evaluation

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing...

1 affected package

gnome-remote-desktop

Package 22.04 LTS
gnome-remote-desktop Needs evaluation
Show less packages

CVE-2026-64607

Medium priority
Needs evaluation

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the...

2 affected packages

commons-httpclient, httpcomponents-client

Package 22.04 LTS
commons-httpclient Needs evaluation
httpcomponents-client Needs evaluation
Show less packages

CVE-2026-15722

Medium priority
Needs evaluation

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer...

1 affected package

389-ds-base

Package 22.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-11770

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against...

1 affected package

389-ds-base

Package 22.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-63223

Medium priority

Not in release

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content...

1 affected package

php-codeigniter-framework

Package 22.04 LTS
php-codeigniter-framework Not in release
Show less packages