Search CVE reports


Toggle filters

441 – 450 of 53339 results

Status is adjusted based on your filters.


CVE-2025-1218

Medium priority
Needs evaluation

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 22.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Not in release
php7.4 Not in release
php8.1 Needs evaluation
php8.3 Not in release
php8.5 Not in release
Show all 7 packages Show less packages

CVE-2026-93682

Medium priority
Needs evaluation

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 22.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Not in release
php7.4 Not in release
php8.1 Needs evaluation
php8.3 Not in release
php8.5 Not in release
Show all 7 packages Show less packages

CVE-2026-100310

Medium priority
Needs evaluation

GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX...

1 affected package

libextractor

Package 22.04 LTS
libextractor Needs evaluation
Show less packages

CVE-2026-55217

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the...

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-55214

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the...

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-53629

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a...

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-53628

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable...

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-53627

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform...

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-53626

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A...

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-53625

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using...

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages