Search CVE reports


Toggle filters

91 – 100 of 36094 results

Status is adjusted based on your filters.


CVE-2025-15570

Medium priority
Needs evaluation

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has...

1 affected package

lrzip

Package 22.04 LTS
lrzip Needs evaluation
Show less packages

CVE-2025-15569

Medium priority
Ignored

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local...

1 affected package

mupdf

Package 22.04 LTS
mupdf Ignored
Show less packages

CVE-2026-23901

Medium priority
Needs evaluation

Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7,...

1 affected package

shiro

Package 22.04 LTS
shiro Needs evaluation
Show less packages

CVE-2026-21218

Medium priority

Some fixes available 1 of 3

Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

5 affected packages

dotnet6, dotnet7, dotnet8, dotnet9, dotnet10

Package 22.04 LTS
dotnet6 Needs evaluation
dotnet7 Ignored
dotnet8 Fixed
dotnet9 Not in release
dotnet10 Not in release
Show less packages

CVE-2026-1584

High priority
Not affected

A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server.

1 affected package

gnutls28

Package 22.04 LTS
gnutls28 Not affected
Show less packages

CVE-2026-25934

Medium priority
Needs evaluation

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified....

1 affected package

golang-github-go-git-go-git

Package 22.04 LTS
golang-github-go-git-go-git Needs evaluation
Show less packages

CVE-2026-25918

Medium priority
Needs evaluation

unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line...

1 affected package

unity

Package 22.04 LTS
unity Needs evaluation
Show less packages

CVE-2026-25892

Medium priority
Needs evaluation

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version....

1 affected package

adminer

Package 22.04 LTS
adminer Needs evaluation
Show less packages

CVE-2026-25765

Medium priority
Needs evaluation

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the...

1 affected package

ruby-faraday

Package 22.04 LTS
ruby-faraday Needs evaluation
Show less packages

CVE-2026-25639

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An...

1 affected package

node-axios

Package 22.04 LTS
node-axios Needs evaluation
Show less packages