Search CVE reports


Toggle filters

1331 – 1340 of 42804 results

Status is adjusted based on your filters.


CVE-2026-26157

Medium priority
Needs evaluation

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the...

1 affected package

busybox

Package 18.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-25994

High priority
Fixed

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

1 affected package

pjproject

Package 18.04 LTS
pjproject Fixed
Show less packages

CVE-2026-25924

Medium priority
Needs evaluation

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution...

2 affected packages

kanboard-cli, python-kanboard

Package 18.04 LTS
kanboard-cli Needs evaluation
python-kanboard Needs evaluation
Show less packages

CVE-2020-37182

High priority
Vulnerable

Redir 3.3 contains a stack overflow vulnerability in the doproxyconnect() function that allows attackers to crash the application by sending oversized input. Attackers can exploit the sprintf() buffer without proper length...

1 affected package

redir

Package 18.04 LTS
redir Vulnerable
Show less packages

CVE-2025-69873

Medium priority
Needs evaluation

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference),...

1 affected package

node-ajv

Package 18.04 LTS
node-ajv Needs evaluation
Show less packages

CVE-2026-26079

Medium priority
Vulnerable

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

1 affected package

roundcube

Package 18.04 LTS
roundcube Vulnerable
Show less packages

CVE-2026-2361

Medium priority
Not affected

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then...

8 affected packages

postgresql-18, postgresql-17, postgresql-16, postgresql-14, postgresql-12...

Package 18.04 LTS
postgresql-18
postgresql-17
postgresql-16
postgresql-14
postgresql-12
postgresql-10 Not affected
postgresql-9.5
postgresql-9.3
Show all 8 packages Show less packages

CVE-2025-69871

Medium priority
Needs evaluation

A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage...

1 affected package

medusa

Package 18.04 LTS
medusa Needs evaluation
Show less packages

CVE-2025-12474

Low priority
Needs evaluation

A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An...

1 affected package

graphicsmagick

Package 18.04 LTS
graphicsmagick Needs evaluation
Show less packages

CVE-2026-26007

Medium priority
Needs evaluation

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or...

1 affected package

python-cryptography

Package 18.04 LTS
python-cryptography Needs evaluation
Show less packages