Search CVE reports


Toggle filters

261 – 270 of 35526 results

Status is adjusted based on your filters.


CVE-2025-68158

Medium priority
Needs evaluation

Authlib is a Python library which builds OAuth and OpenID Connect servers. In version 1.6.5 and prior, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that...

1 affected package

python-authlib

Package 22.04 LTS
python-authlib Needs evaluation
Show less packages

CVE-2026-22028

Medium priority
Needs evaluation

Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be...

1 affected package

node-preact

Package 22.04 LTS
node-preact Needs evaluation
Show less packages

CVE-2025-66003

Medium priority
Needs evaluation

An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba shareThis issue affects smb4k: from ?...

1 affected package

smb4k

Package 22.04 LTS
smb4k Needs evaluation
Show less packages

CVE-2025-66002

Medium priority
Needs evaluation

An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper

1 affected package

smb4k

Package 22.04 LTS
smb4k Needs evaluation
Show less packages

CVE-2026-21895

Medium priority

Not in release

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version...

1 affected package

rust-rsa

Package 22.04 LTS
rust-rsa Not in release
Show less packages

CVE-2026-21892

Medium priority

Not in release

Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsafe string formatting (Python %...

1 affected package

python-parsl

Package 22.04 LTS
python-parsl Not in release
Show less packages

CVE-2026-21885

Medium priority

Not in release

Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can...

1 affected package

miniflux

Package 22.04 LTS
miniflux Not in release
Show less packages

CVE-2026-21876

Medium priority
Needs evaluation

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests...

1 affected package

modsecurity-crs

Package 22.04 LTS
modsecurity-crs Needs evaluation
Show less packages

CVE-2026-0719

Medium priority
Vulnerable

A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can...

2 affected packages

libsoup2.4, libsoup3

Package 22.04 LTS
libsoup2.4 Vulnerable
libsoup3 Vulnerable
Show less packages

CVE-2026-21869

Medium priority

Not in release

llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is parsed directly from JSON input in the llama.cpp server's completion endpoints without validation to ensure it's...

1 affected package

llama.cpp

Package 22.04 LTS
llama.cpp Not in release
Show less packages