Search CVE reports


Toggle filters

3071 – 3080 of 39618 results

Status is adjusted based on your filters.


CVE-2026-1225

Medium priority
Needs evaluation

ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising...

1 affected package

logback

Package 20.04 LTS
logback Needs evaluation
Show less packages

CVE-2026-24049

Medium priority
Needs evaluation

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions...

2 affected packages

wheel, python-pip

Package 20.04 LTS
wheel Not affected
python-pip Needs evaluation
Show less packages

CVE-2025-71176

Medium priority
Needs evaluation

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

1 affected package

pytest

Package 20.04 LTS
pytest Needs evaluation
Show less packages

CVE-2026-24001

Medium priority
Needs evaluation

jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause...

1 affected package

node-diff

Package 20.04 LTS
node-diff Needs evaluation
Show less packages

CVE-2026-23952

Medium priority
Fixed

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Fixed
Show less packages

CVE-2026-23893

Medium priority
Needs evaluation

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations...

1 affected package

opencryptoki

Package 20.04 LTS
opencryptoki Needs evaluation
Show less packages

CVE-2025-13465

Medium priority
Needs evaluation

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits...

1 affected package

node-lodash

Package 20.04 LTS
node-lodash Needs evaluation
Show less packages

CVE-2025-12781

Medium priority
Ignored

When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to...

13 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 20.04 LTS
pypy3 Ignored
python2.7 Ignored
python3.4
python3.5
python3.6
python3.7
python3.8 Ignored
python3.9 Ignored
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 13 packages Show less packages

CVE-2021-47865

Medium priority
Needs evaluation

ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust...

1 affected package

proftpd-dfsg

Package 20.04 LTS
proftpd-dfsg Needs evaluation
Show less packages

CVE-2021-47853

Medium priority
Not affected

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

1 affected package

phppgadmin

Package 20.04 LTS
phppgadmin Not affected
Show less packages