Search CVE reports


Toggle filters

2981 – 2990 of 49990 results

Status is adjusted based on your filters.


CVE-2025-67852

Medium priority
Needs evaluation

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2025-67851

Medium priority
Needs evaluation

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2025-67850

Medium priority
Needs evaluation

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2025-67849

Medium priority
Needs evaluation

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2025-67848

Medium priority
Needs evaluation

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-1703

Low priority
Vulnerable

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to...

1 affected package

python-pip

Package 16.04 LTS
python-pip Vulnerable
Show less packages

CVE-2026-1761

Medium priority
Needs evaluation

A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2026-1760

Medium priority
Needs evaluation

A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated...

2 affected packages

libsoup2.4, libsoup3

Package 16.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2026-1757

Low priority
Not affected

A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only...

1 affected package

libxml2

Package 16.04 LTS
libxml2 Not affected
Show less packages

CVE-2026-1751

Medium priority
Ignored

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages