Search CVE reports


Toggle filters

1021 – 1030 of 33231 results

Status is adjusted based on your filters.


CVE-2019-25452

Medium priority

Not in release

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST...

1 affected package

dolibarr

Package 24.04 LTS
dolibarr Not in release
Show less packages

CVE-2019-25450

Medium priority

Not in release

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through...

1 affected package

dolibarr

Package 24.04 LTS
dolibarr Not in release
Show less packages

CVE-2026-2913

Medium priority
Needs evaluation

A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffer overflow. It is possible to...

1 affected package

vips

Package 24.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-2903

Low priority
Vulnerable

A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src/parse/ast.cc. This manipulation causes null pointer dereference. The attack can only be executed locally. The...

1 affected package

re2c

Package 24.04 LTS
re2c Vulnerable
Show less packages

CVE-2026-2889

Medium priority
Needs evaluation

A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access....

1 affected package

ccextractor

Package 24.04 LTS
ccextractor Needs evaluation
Show less packages

CVE-2026-27470

Medium priority
Needs evaluation

ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the web/ajax/status.php file within...

1 affected package

zoneminder

Package 24.04 LTS
zoneminder Needs evaluation
Show less packages

CVE-2026-27206

Medium priority
Needs evaluation

Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The deserializer instantiates any...

1 affected package

php-zumba-json-serializer

Package 24.04 LTS
php-zumba-json-serializer Needs evaluation
Show less packages

CVE-2026-27205

Low priority
Fixed

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache...

1 affected package

flask

Package 24.04 LTS
flask Fixed
Show less packages

CVE-2026-27199

Medium priority
Not affected

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previously reported...

1 affected package

python-werkzeug

Package 24.04 LTS
python-werkzeug Not affected
Show less packages

CVE-2026-26047

Medium priority

Not in release

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server...

1 affected package

moodle

Package 24.04 LTS
moodle Not in release
Show less packages