Search CVE reports


Toggle filters

2341 – 2350 of 37984 results

Status is adjusted based on your filters.


CVE-2026-24476

Medium priority

Not in release

Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` prematurely ends the `<input>` tag on the start page and allows an attacker to add arbitrary html leading to a...

1 affected package

shaarli

Package 22.04 LTS
shaarli Not in release
Show less packages

CVE-2026-24400

Medium priority
Needs evaluation

AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists...

1 affected package

assertj-core

Package 22.04 LTS
assertj-core Needs evaluation
Show less packages

CVE-2026-0810

Medium priority

Not in release

A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to...

1 affected package

rust-gix-date

Package 22.04 LTS
rust-gix-date Not in release
Show less packages

CVE-2025-9820

Low priority
Fixed

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a...

1 affected package

gnutls28

Package 22.04 LTS
gnutls28 Fixed
Show less packages

CVE-2025-9615

Medium priority
Vulnerable

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and...

1 affected package

network-manager

Package 22.04 LTS
network-manager Vulnerable
Show less packages

CVE-2025-11687

Medium priority
Needs evaluation

A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page — enabling DOM access, session cookie theft and other client-side attacks — via a crafted URL that supplies a...

1 affected package

gi-docgen

Package 22.04 LTS
gi-docgen Needs evaluation
Show less packages

CVE-2025-11065

Medium priority

Not in release

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive...

1 affected package

golang-github-go-viper-mapstructure

Package 22.04 LTS
golang-github-go-viper-mapstructure Not in release
Show less packages

CVE-2025-50537

Medium priority
Needs evaluation

Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the RuleTester.run() method, which validates test cases and...

1 affected package

eslint

Package 22.04 LTS
eslint Needs evaluation
Show less packages

CVE-2026-1425

Medium priority
Needs evaluation

A security flaw has been discovered in pymumu SmartDNS up to 47.1. This vulnerability affects the function _dns_decode_rr_head/_dns_decode_SVCB_HTTPS of the file src/dns.c of the component SVBC Record Parser. The manipulation...

1 affected package

smartdns

Package 22.04 LTS
smartdns Needs evaluation
Show less packages

CVE-2026-1418

Medium priority
Needs evaluation

A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_to_bifs.c of the component SRT Subtitle Import. Such manipulation leads to...

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages