Search CVE reports


Toggle filters

2011 – 2020 of 45973 results

Status is adjusted based on your filters.


CVE-2026-28946

Medium priority

Some fixes available 1 of 2

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-77648

Medium priority
Needs evaluation

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http://...

1 affected package

glance

Package 24.04 LTS
glance Needs evaluation
Show less packages

CVE-2026-77647

Medium priority
Needs evaluation

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain...

1 affected package

spip

Package 24.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-77643

Medium priority
Needs evaluation

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because...

1 affected package

xapian-core

Package 24.04 LTS
xapian-core Needs evaluation
Show less packages

CVE-2026-77642

Medium priority
Needs evaluation

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities....

1 affected package

tor

Package 24.04 LTS
tor Needs evaluation
Show less packages

CVE-2026-72818

Medium priority
Needs evaluation

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-55894

Medium priority
Needs evaluation

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active...

1 affected package

capstone

Package 24.04 LTS
capstone Needs evaluation
Show less packages

CVE-2026-55893

Medium priority
Needs evaluation

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without...

1 affected package

capstone

Package 24.04 LTS
capstone Needs evaluation
Show less packages

CVE-2026-77641

Medium priority
Needs evaluation

tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and...

1 affected package

tor

Package 24.04 LTS
tor Needs evaluation
Show less packages

CVE-2026-77640

Medium priority
Needs evaluation

tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which ...

1 affected package

tor

Package 24.04 LTS
tor Needs evaluation
Show less packages