Search CVE reports


Toggle filters

31 – 40 of 526 results


CVE-2026-30924

Medium priority
Needs evaluation

qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials: true, effectively allowing...

1 affected package

qbittorrent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qbittorrent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-31958

Medium priority
Fixed

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing...

1 affected package

python-tornado

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-28343

Medium priority
Needs evaluation

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support...

4 affected packages

ckeditor, ldap-account-manager, request-tracker4, ckeditor3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor3 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-3172

Medium priority
Needs evaluation

Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.

1 affected package

pgvector

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pgvector Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-2889

Medium priority
Needs evaluation

A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access....

1 affected package

ccextractor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ccextractor Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-2245

Medium priority
Needs evaluation

A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation leads to out-of-bounds read. The...

1 affected package

ccextractor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ccextractor Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-24747

Medium priority
Needs evaluation

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with...

1 affected package

pytorch

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pytorch Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2026-24137

Medium priority
Needs evaluation

sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path...

1 affected package

golang-github-sigstore-sigstore

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sigstore-sigstore Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-22772

Medium priority
Needs evaluation

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer...

1 affected package

golang-github-sigstore-fulcio

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sigstore-fulcio Needs evaluation Not in release Not in release
Show less packages

CVE-2025-67726

Medium priority
Fixed

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in...

1 affected package

python-tornado

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Not affected Fixed Fixed Fixed Fixed
Show less packages