Search CVE reports


Toggle filters

531 – 540 of 45341 results

Status is adjusted based on your filters.


CVE-2026-59314

Medium priority
Needs evaluation

Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 -...

1 affected package

libspring-java

Package 24.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-59313

Medium priority
Needs evaluation

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 -...

1 affected package

libspring-java

Package 24.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-59283

Medium priority
Needs evaluation

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8 Spring...

1 affected package

libspring-java

Package 24.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-59282

Medium priority
Needs evaluation

Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring...

1 affected package

libspring-java

Package 24.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-59281

Medium priority
Needs evaluation

Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors...

1 affected package

libspring-java

Package 24.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-18374

Medium priority
Vulnerable

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the...

2 affected packages

glibc, eglibc

Package 24.04 LTS
glibc Vulnerable
eglibc Not in release
Show less packages

CVE-2026-81727

Medium priority
Needs evaluation

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81726

Medium priority
Needs evaluation

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81725

Medium priority
Needs evaluation

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags....

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81724

Medium priority
Needs evaluation

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input....

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages