Search CVE reports


Toggle filters

531 – 540 of 37473 results

Status is adjusted based on your filters.


CVE-2026-79590

Medium priority
Needs evaluation

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling...

1 affected package

mruby

Package 26.04 LTS
mruby Needs evaluation
Show less packages

CVE-2026-79516

Medium priority
Needs evaluation

An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-79515

Medium priority
Needs evaluation

An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-78807

Medium priority
Needs evaluation

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

1 affected package

wpa

Package 26.04 LTS
wpa Needs evaluation
Show less packages

CVE-2026-78030

Medium priority
Needs evaluation

[Unknown description]

1 affected package

libdbi-perl

Package 26.04 LTS
libdbi-perl Needs evaluation
Show less packages

CVE-2026-77159

Medium priority
Needs evaluation

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm...

2 affected packages

libvirt, libvirt-hwe

Package 26.04 LTS
libvirt Needs evaluation
libvirt-hwe Needs evaluation
Show less packages

CVE-2026-72710

Medium priority
Needs evaluation

SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce...

1 affected package

spip

Package 26.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-72709

Medium priority
Needs evaluation

SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256...

1 affected package

spip

Package 26.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-72708

Medium priority
Needs evaluation

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unescaped when the target column is a...

1 affected package

spip

Package 26.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-68497

Medium priority
Needs evaluation

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in...

1 affected package

jackson-databind

Package 26.04 LTS
jackson-databind Needs evaluation
Show less packages