Search CVE reports


Toggle filters

521 – 530 of 37431 results

Status is adjusted based on your filters.


CVE-2026-33154

Medium priority
Needs evaluation

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is...

1 affected package

python-dynaconf

Package 22.04 LTS
python-dynaconf Needs evaluation
Show less packages

CVE-2026-33151

Medium priority
Needs evaluation

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary...

1 affected package

node-socket.io-parser

Package 22.04 LTS
node-socket.io-parser Needs evaluation
Show less packages

CVE-2026-33150

Medium priority
Not affected

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem...

2 affected packages

fuse, fuse3

Package 22.04 LTS
fuse Not affected
fuse3 Not affected
Show less packages

CVE-2026-33144

Medium priority
Needs evaluation

GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in...

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-63261

Low priority
Needs evaluation

AWStats 8.0 is vulnerable to Command Injection via the open function

1 affected package

awstats

Package 22.04 LTS
awstats Needs evaluation
Show less packages

CVE-2026-4438

Medium priority
Needs evaluation

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the...

2 affected packages

glibc, eglibc

Package 22.04 LTS
glibc Needs evaluation
eglibc Not in release
Show less packages

CVE-2026-4437

Medium priority
Needs evaluation

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server,...

2 affected packages

glibc, eglibc

Package 22.04 LTS
glibc Needs evaluation
eglibc Not in release
Show less packages

CVE-2026-32710

Medium priority
Needs evaluation

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might...

5 affected packages

mariadb, mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.6

Package 22.04 LTS
mariadb Not in release
mariadb-10.0 Not in release
mariadb-10.1 Not in release
mariadb-10.3 Not in release
mariadb-10.6 Needs evaluation
Show less packages

CVE-2026-4519

Medium priority
Needs evaluation

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing...

14 affected packages

jython, pypy3, python2.7, python3.4, python3.5...

Package 22.04 LTS
jython Needs evaluation
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Needs evaluation
python3.11 Needs evaluation
python3.12 Not in release
python3.13 Not in release
python3.14 Not in release
Show all 14 packages Show less packages

CVE-2026-33123

Medium priority

Not in release

pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based...

1 affected package

pypdf

Package 22.04 LTS
pypdf Not in release
Show less packages