Search CVE reports


Toggle filters

2921 – 2930 of 49652 results

Status is adjusted based on your filters.


CVE-2025-15536

Medium priority
Needs evaluation

A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The...

1 affected package

opencc

Package 16.04 LTS
opencc Needs evaluation
Show less packages

CVE-2026-22865

Medium priority
Needs evaluation

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...

1 affected package

gradle

Package 16.04 LTS
gradle Needs evaluation
Show less packages

CVE-2026-22816

Medium priority
Needs evaluation

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a...

1 affected package

gradle

Package 16.04 LTS
gradle Needs evaluation
Show less packages

CVE-2026-23745

Medium priority
Needs evaluation

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to...

1 affected package

node-tar

Package 16.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2026-23643

Medium priority
Needs evaluation

CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.

1 affected package

cakephp

Package 16.04 LTS
cakephp Needs evaluation
Show less packages

CVE-2026-23490

Medium priority
Fixed

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

1 affected package

pyasn1

Package 16.04 LTS
pyasn1 Fixed
Show less packages

CVE-2025-61873

Medium priority
Needs evaluation

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

2 affected packages

request-tracker4, request-tracker5

Package 16.04 LTS
request-tracker4 Needs evaluation
request-tracker5
Show less packages

CVE-2025-51602

Medium priority
Needs evaluation

mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server.

1 affected package

vlc

Package 16.04 LTS
vlc Needs evaluation
Show less packages

CVE-2025-31510

Medium priority
Needs evaluation

In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.

1 affected package

lemonldap-ng

Package 16.04 LTS
lemonldap-ng Needs evaluation
Show less packages

CVE-2026-0988

Medium priority
Vulnerable

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this...

1 affected package

glib2.0

Package 16.04 LTS
glib2.0 Vulnerable
Show less packages