Search CVE reports


Toggle filters

651 – 660 of 50787 results

Status is adjusted based on your filters.


CVE-2026-89329

Medium priority
Needs evaluation

A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause...

1 affected package

multipath-tools

Package 22.04 LTS
multipath-tools Needs evaluation
Show less packages

CVE-2026-89099

Medium priority

Not in release

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-87910

Medium priority
Needs evaluation

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to...

12 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 22.04 LTS
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Needs evaluation
python3.11 Needs evaluation
python3.12 Not in release
python3.14 Not in release
Show all 12 packages Show less packages

CVE-2026-82617

Medium priority
Needs evaluation

The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URLĀ - contain ambiguous nested quantifiers. An application that obtains...

1 affected package

apache-opennlp

Package 22.04 LTS
apache-opennlp Needs evaluation
Show less packages

CVE-2026-78807

Medium priority
Needs evaluation

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

1 affected package

wpa

Package 22.04 LTS
wpa Needs evaluation
Show less packages

CVE-2026-67211

Medium priority
Needs evaluation

OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not...

1 affected package

apache-opennlp

Package 22.04 LTS
apache-opennlp Needs evaluation
Show less packages

CVE-2026-18495

Medium priority
Needs evaluation

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file,...

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 22.04 LTS
tiff Needs evaluation
qtwebengine-opensource-src Needs evaluation
texmaker Needs evaluation
gdal Not affected
neuron Needs evaluation
Show less packages

CVE-2026-72710

Medium priority
Needs evaluation

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-72709

Medium priority
Needs evaluation

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-72708

Medium priority
Needs evaluation

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages