Search CVE reports


Toggle filters

241 – 250 of 36755 results

Status is adjusted based on your filters.


CVE-2026-27810

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, an HTTP Response Header Injection vulnerability in the calibre Content Server allows any authenticated...

1 affected package

calibre

Package 22.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-21619

Medium priority
Needs evaluation

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive...

2 affected packages

rebar3, erlang-hex

Package 22.04 LTS
rebar3 Needs evaluation
erlang-hex Not in release
Show less packages

CVE-2025-10990

Medium priority
Vulnerable

A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 22.04 LTS
ruby2.3 Not in release
ruby2.5 Not in release
ruby2.7 Not in release
ruby3.0 Vulnerable
ruby3.2 Not in release
ruby3.3 Not in release
jruby Not in release
Show all 7 packages Show less packages

CVE-2026-24352

Medium priority
Needs evaluation

PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack...

1 affected package

pluxml

Package 22.04 LTS
pluxml Needs evaluation
Show less packages

CVE-2026-24351

Medium priority
Needs evaluation

PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor...

1 affected package

pluxml

Package 22.04 LTS
pluxml Needs evaluation
Show less packages

CVE-2026-24350

Medium priority
Needs evaluation

PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated with the...

1 affected package

pluxml

Package 22.04 LTS
pluxml Needs evaluation
Show less packages

CVE-2025-9572

Medium priority
Needs evaluation

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply...

1 affected package

ruby-foreman

Package 22.04 LTS
ruby-foreman Needs evaluation
Show less packages

CVE-2026-2597

Medium priority

Not in release

Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_bytes(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1)...

1 affected package

libcrypt-sysrandom-xs-perl

Package 22.04 LTS
libcrypt-sysrandom-xs-perl Not in release
Show less packages

CVE-2026-3284

Medium priority
Needs evaluation

A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires...

1 affected package

vips

Package 22.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3283

Medium priority
Needs evaluation

A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_band leads to out-of-bounds read. The...

1 affected package

vips

Package 22.04 LTS
vips Needs evaluation
Show less packages