Search CVE reports


Toggle filters

551 – 560 of 37501 results

Status is adjusted based on your filters.


CVE-2026-67211

Medium priority
Needs evaluation

OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not...

1 affected package

apache-opennlp

Package 26.04 LTS
apache-opennlp Needs evaluation
Show less packages

CVE-2026-18495

Medium priority
Needs evaluation

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file,...

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 26.04 LTS
tiff Needs evaluation
qtwebengine-opensource-src Needs evaluation
texmaker Not affected
gdal Not affected
neuron Not affected
Show less packages

CVE-2026-72710

Medium priority
Needs evaluation

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an...

1 affected package

spip

Package 26.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-72709

Medium priority
Needs evaluation

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without...

1 affected package

spip

Package 26.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-72708

Medium priority
Needs evaluation

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word...

1 affected package

spip

Package 26.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-68497

Medium priority
Needs evaluation

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in...

1 affected package

jackson-databind

Package 26.04 LTS
jackson-databind Needs evaluation
Show less packages

CVE-2026-87020

Medium priority
Needs evaluation

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

1 affected package

orthanc

Package 26.04 LTS
orthanc Needs evaluation
Show less packages

CVE-2026-85979

Medium priority
Needs evaluation

Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell...

1 affected package

puppetserver

Package 26.04 LTS
puppetserver Needs evaluation
Show less packages

CVE-2026-89259

Medium priority
Needs evaluation

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive...

1 affected package

hugo

Package 26.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-89258

Medium priority
Needs evaluation

Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place —...

1 affected package

hugo

Package 26.04 LTS
hugo Needs evaluation
Show less packages