Search CVE reports


Toggle filters

2611 – 2620 of 46511 results

Status is adjusted based on your filters.


CVE-2026-15686

Medium priority
Needs evaluation

Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is...

1 affected package

adminer

Package 24.04 LTS
adminer Needs evaluation
Show less packages

CVE-2026-75140

Medium priority
Needs evaluation

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with...

1 affected package

jsoup

Package 24.04 LTS
jsoup Needs evaluation
Show less packages

CVE-2026-55558

Medium priority

Not in release

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without...

1 affected package

aiosmtplib

Package 24.04 LTS
aiosmtplib Not in release
Show less packages

CVE-2026-49825

Medium priority
Needs evaluation

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in...

1 affected package

lxml

Package 24.04 LTS
lxml Needs evaluation
Show less packages

CVE-2026-77118

Medium priority
Needs evaluation

A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against...

1 affected package

graphicsmagick

Package 24.04 LTS
graphicsmagick Needs evaluation
Show less packages

CVE-2026-7485

Medium priority

Not in release

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of...

1 affected package

check-mk

Package 24.04 LTS
check-mk Not in release
Show less packages

CVE-2026-73198

Medium priority
Needs evaluation

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory,...

1 affected package

freeipa

Package 24.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-73197

Medium priority
Needs evaluation

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read...

1 affected package

freeipa

Package 24.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-73196

Medium priority
Needs evaluation

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size...

1 affected package

freeipa

Package 24.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-13097

Medium priority
Needs evaluation

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the...

1 affected package

freeipa

Package 24.04 LTS
freeipa Needs evaluation
Show less packages