Search CVE reports


Toggle filters

1 – 10 of 36284 results

Status is adjusted based on your filters.


CVE-2026-27475

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27474

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27473

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27472

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing a syndicated site, the application does not verify that the syndication URL is a valid remote URL, allowing...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27206

Medium priority

Not in release

[Potential PHP Object Injection via Unrestricted @type in unserialize()]

1 affected package

php-zumba-json-serializer

Package 22.04 LTS
php-zumba-json-serializer Not in release
Show less packages

CVE-2026-2705

Medium priority
Needs evaluation

A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The manipulation results in...

1 affected package

openbabel

Package 22.04 LTS
openbabel Needs evaluation
Show less packages

CVE-2026-2704

Medium priority
Needs evaluation

A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file src/math/transform3d.cpp of the component CIF File Handler....

1 affected package

openbabel

Package 22.04 LTS
openbabel Needs evaluation
Show less packages

CVE-2026-26963

Medium priority
Needs evaluation

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption...

1 affected package

golang-github-cilium-ebpf

Package 22.04 LTS
golang-github-cilium-ebpf Needs evaluation
Show less packages

CVE-2026-26345

Medium priority
Needs evaluation

SPIP before 4.4.8 allows Cross-Site Scripting (XSS) in the public area for certain edge-case usage patterns. The echapper_html_suspect() function does not adequately detect all forms of malicious content, permitting an attacker to...

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-26278

Medium priority

Not in release

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited...

1 affected package

node-webfont

Package 22.04 LTS
node-webfont Not in release
Show less packages