Search CVE reports


Toggle filters

441 – 450 of 35718 results

Status is adjusted based on your filters.


CVE-2025-10569

Medium priority

Not in release

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by...

1 affected package

gitlab

Package 22.04 LTS
gitlab Not in release
Show less packages

CVE-2025-69195

Medium priority
Needs evaluation

A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active....

1 affected package

wget2

Package 22.04 LTS
wget2 Needs evaluation
Show less packages

CVE-2025-69194

Medium priority
Needs evaluation

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to...

1 affected package

wget2

Package 22.04 LTS
wget2 Needs evaluation
Show less packages

CVE-2025-14505

Medium priority
Needs evaluation

The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is...

1 affected package

node-elliptic

Package 22.04 LTS
node-elliptic Needs evaluation
Show less packages

CVE-2026-21860

Medium priority
Not affected

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are...

1 affected package

python-werkzeug

Package 22.04 LTS
python-werkzeug Not affected
Show less packages

CVE-2025-68158

Medium priority
Needs evaluation

Authlib is a Python library which builds OAuth and OpenID Connect servers. In version 1.6.5 and prior, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that...

1 affected package

python-authlib

Package 22.04 LTS
python-authlib Needs evaluation
Show less packages

CVE-2026-22028

Medium priority
Needs evaluation

Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be...

1 affected package

node-preact

Package 22.04 LTS
node-preact Needs evaluation
Show less packages

CVE-2025-66003

Medium priority
Needs evaluation

An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba shareThis issue affects smb4k: from ?...

1 affected package

smb4k

Package 22.04 LTS
smb4k Needs evaluation
Show less packages

CVE-2025-66002

Medium priority
Needs evaluation

An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper

1 affected package

smb4k

Package 22.04 LTS
smb4k Needs evaluation
Show less packages

CVE-2026-21895

Medium priority

Not in release

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version...

1 affected package

rust-rsa

Package 22.04 LTS
rust-rsa Not in release
Show less packages