Search CVE reports


Toggle filters

2041 – 2050 of 45973 results

Status is adjusted based on your filters.


CVE-2026-15743

Medium priority
Needs evaluation

Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies...

1 affected package

libcatalyst-plugin-static-simple-perl

Package 24.04 LTS
libcatalyst-plugin-static-simple-perl Needs evaluation
Show less packages

CVE-2026-76641

Medium priority
Vulnerable

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch...

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS
expat Vulnerable
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-73259

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it....

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73258

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73257

Medium priority

Not in release

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73256

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73255

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73254

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73253

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack....

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73251

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init()...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages