Search CVE reports


Toggle filters

591 – 600 of 36910 results

Status is adjusted based on your filters.


CVE-2026-27470

Medium priority
Needs evaluation

ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the web/ajax/status.php file within...

1 affected package

zoneminder

Package 22.04 LTS
zoneminder Needs evaluation
Show less packages

CVE-2026-27206

Medium priority

Not in release

Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The deserializer instantiates any...

1 affected package

php-zumba-json-serializer

Package 22.04 LTS
php-zumba-json-serializer Not in release
Show less packages

CVE-2026-27205

Low priority
Fixed

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache...

1 affected package

flask

Package 22.04 LTS
flask Fixed
Show less packages

CVE-2026-27199

Medium priority
Not affected

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previously reported...

1 affected package

python-werkzeug

Package 22.04 LTS
python-werkzeug Not affected
Show less packages

CVE-2026-26047

Medium priority

Not in release

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server...

1 affected package

moodle

Package 22.04 LTS
moodle Not in release
Show less packages

CVE-2026-26046

Medium priority

Not in release

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a...

1 affected package

moodle

Package 22.04 LTS
moodle Not in release
Show less packages

CVE-2026-26045

Medium priority

Not in release

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of...

1 affected package

moodle

Package 22.04 LTS
moodle Not in release
Show less packages

CVE-2026-27168

Medium priority

Not in release

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. All versions are vulnerable to Heap-based Buffer Overflow through the XWD parser's use of the bytes_per_line...

1 affected package

sail

Package 22.04 LTS
sail Not in release
Show less packages

CVE-2026-2492

Medium priority

Not in release

TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker must first...

1 affected package

tensorflow

Package 22.04 LTS
tensorflow Not in release
Show less packages

CVE-2026-2048

Medium priority
Needs evaluation

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 22.04 LTS
gimp Needs evaluation
Show less packages