Search CVE reports


Toggle filters

11 – 20 of 36284 results

Status is adjusted based on your filters.


CVE-2026-26223

Medium priority
Needs evaluation

SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the private area via malicious iframe tags. The application does not properly sandbox or escape iframe content in the back-office, allowing an attacker to inject and execute...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-26203

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams...

1 affected package

pjproject

Package 22.04 LTS
pjproject Not in release
Show less packages

CVE-2026-26200

Medium priority
Needs evaluation

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and...

1 affected package

hdf5

Package 22.04 LTS
hdf5 Needs evaluation
Show less packages

CVE-2026-25766

Medium priority
Not affected

Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote file read outside the static...

3 affected packages

golang-github-labstack-echo, golang-github-labstack-echo.v2, golang-github-labstack-echo.v3

Package 22.04 LTS
golang-github-labstack-echo Not affected
golang-github-labstack-echo.v2 Not affected
golang-github-labstack-echo.v3 Not affected
Show less packages

CVE-2026-24122

Medium priority

Not in release

Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification...

1 affected package

cosign

Package 22.04 LTS
cosign Not in release
Show less packages

CVE-2026-2243

Medium priority
Needs evaluation

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).

1 affected package

qemu

Package 22.04 LTS
qemu Needs evaluation
Show less packages

CVE-2025-71244

Medium priority
Needs evaluation

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login....

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2025-71242

Medium priority
Needs evaluation

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2025-71241

Medium priority
Needs evaluation

SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error message displayed by the 'transmettre' API is not properly sanitized, allowing an attacker to inject malicious...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2025-71240

Medium priority
Needs evaluation

SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not properly verify JavaScript within code tags, allowing an attacker to inject malicious scripts that execute in a...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages