Search CVE reports


Toggle filters

21 – 30 of 42531 results

Status is adjusted based on your filters.


CVE-2026-39897

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_footer. This issue has been fixed in version 1.2.31.

1 affected package

cacti

Package 22.04 LTS
cacti Needs evaluation
Show less packages

CVE-2026-39894

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt RRDtool metric values....

1 affected package

cacti

Package 22.04 LTS
cacti Needs evaluation
Show less packages

CVE-2026-39893

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without sanitization. The endpoint does not...

1 affected package

cacti

Package 22.04 LTS
cacti Needs evaluation
Show less packages

CVE-2026-33612

Medium priority
Needs evaluation

security update

1 affected package

pdns-recursor

Package 22.04 LTS
pdns-recursor Needs evaluation
Show less packages

CVE-2026-23879

Medium priority
Needs evaluation

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to...

1 affected package

py7zr

Package 22.04 LTS
py7zr Needs evaluation
Show less packages

CVE-2026-13311

Medium priority
Needs evaluation

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time...

1 affected package

node-shell-quote

Package 22.04 LTS
node-shell-quote Needs evaluation
Show less packages

CVE-2026-12844

Medium priority
Needs evaluation

(List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer o ...)

1 affected package

liblist-someutils-xs-perl

Package 22.04 LTS
liblist-someutils-xs-perl Needs evaluation
Show less packages

CVE-2026-11999

Medium priority
Vulnerable

(X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compat ...)

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 22.04 LTS
openssl Needs evaluation
openssl-fips Not in release
openssl1.0 Not in release
nodejs Vulnerable
edk2 Needs evaluation
Show less packages

CVE-2026-11998

Medium priority
Needs evaluation

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose...

1 affected package

angular.js

Package 22.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2025-60474

Medium priority
Needs evaluation

A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages