Search CVE reports


Toggle filters

471 – 480 of 42163 results

Status is adjusted based on your filters.


CVE-2025-71244

Medium priority
Needs evaluation

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login....

1 affected package

spip

Package 18.04 LTS
spip Needs evaluation
Show less packages

CVE-2025-71242

Medium priority
Needs evaluation

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded...

1 affected package

spip

Package 18.04 LTS
spip Needs evaluation
Show less packages

CVE-2025-71241

Medium priority
Needs evaluation

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious...

1 affected package

spip

Package 18.04 LTS
spip Needs evaluation
Show less packages

CVE-2025-71240

Medium priority
Needs evaluation

SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a...

1 affected package

spip

Package 18.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-2705

Medium priority
Needs evaluation

A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in...

1 affected package

openbabel

Package 18.04 LTS
openbabel Needs evaluation
Show less packages

CVE-2026-2704

Medium priority
Needs evaluation

A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file src/math/transform3d.cpp of the component CIF File Handler....

1 affected package

openbabel

Package 18.04 LTS
openbabel Needs evaluation
Show less packages

CVE-2025-15581

Medium priority
Needs evaluation

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full...

1 affected package

orthanc

Package 18.04 LTS
orthanc Needs evaluation
Show less packages

CVE-2019-25355

Medium priority
Needs evaluation

gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending...

1 affected package

gsoap

Package 18.04 LTS
gsoap Needs evaluation
Show less packages

CVE-2026-1200

Medium priority
Needs evaluation

A flaw was found in the rgaufman/live555 fork of live555. A remote attacker could exploit a segmentation fault, in the `increaseBufferTo` function. This vulnerability can lead to memory corruption problems and potentially other...

1 affected package

liblivemedia

Package 18.04 LTS
liblivemedia Needs evaluation
Show less packages

CVE-2026-0665

Medium priority
Not affected

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial...

1 affected package

qemu

Package 18.04 LTS
qemu Not affected
Show less packages