Search CVE reports


Toggle filters

251 – 260 of 35526 results

Status is adjusted based on your filters.


CVE-2026-22701

Medium priority
Needs evaluation

filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access...

1 affected package

python-filelock

Package 22.04 LTS
python-filelock Needs evaluation
Show less packages

CVE-2026-22693

Low priority
Not affected

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc...

1 affected package

harfbuzz

Package 22.04 LTS
harfbuzz Not affected
Show less packages

CVE-2026-22691

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long...

2 affected packages

pypdf, pypdf2

Package 22.04 LTS
pypdf Not in release
pypdf2 Needs evaluation
Show less packages

CVE-2026-22690

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF...

2 affected packages

pypdf, pypdf2

Package 22.04 LTS
pypdf Not in release
pypdf2 Needs evaluation
Show less packages

CVE-2026-22610

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS)...

1 affected package

angular.js

Package 22.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2025-56225

Medium priority
Needs evaluation

fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.

1 affected package

fluidsynth

Package 22.04 LTS
fluidsynth Needs evaluation
Show less packages

CVE-2025-69195

Medium priority
Needs evaluation

A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active....

1 affected package

wget2

Package 22.04 LTS
wget2 Needs evaluation
Show less packages

CVE-2025-69194

Medium priority
Needs evaluation

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to...

1 affected package

wget2

Package 22.04 LTS
wget2 Needs evaluation
Show less packages

CVE-2025-14505

Medium priority
Needs evaluation

The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is...

1 affected package

node-elliptic

Package 22.04 LTS
node-elliptic Needs evaluation
Show less packages

CVE-2026-21860

Medium priority
Not affected

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are...

1 affected package

python-werkzeug

Package 22.04 LTS
python-werkzeug Not affected
Show less packages