Search CVE reports


Toggle filters

41 – 50 of 49222 results

Status is adjusted based on your filters.


CVE-2026-82397

Medium priority
Needs evaluation

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields....

1 affected package

python-tornado

Package 22.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-81624

Medium priority
Needs evaluation

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts...

1 affected package

undertow

Package 22.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-78422

Medium priority

Not in release

Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a signed...

1 affected package

rust-zbus-polkit

Package 22.04 LTS
rust-zbus-polkit Not in release
Show less packages

CVE-2026-66047

Medium priority
Needs evaluation

ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak...

1 affected package

wordpress

Package 22.04 LTS
wordpress Needs evaluation
Show less packages

CVE-2026-19032

Medium priority
Needs evaluation

jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to...

1 affected package

libjackson-json-java

Package 22.04 LTS
libjackson-json-java Needs evaluation
Show less packages

CVE-2026-18743

Medium priority
Needs evaluation

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how...

1 affected package

popt

Package 22.04 LTS
popt Needs evaluation
Show less packages

CVE-2026-13732

Medium priority
Needs evaluation

A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++...

1 affected package

gdb

Package 22.04 LTS
gdb Needs evaluation
Show less packages

CVE-2024-58379

Medium priority
Needs evaluation

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with...

1 affected package

node-nodemailer

Package 22.04 LTS
node-nodemailer Needs evaluation
Show less packages

CVE-2026-82677

Medium priority

Not in release

A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be...

1 affected package

valkey

Package 22.04 LTS
valkey Not in release
Show less packages

CVE-2026-82631

Medium priority

Not in release

A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in...

1 affected package

valkey

Package 22.04 LTS
valkey Not in release
Show less packages