Search CVE reports


Toggle filters

761 – 770 of 45564 results

Status is adjusted based on your filters.


CVE-2026-81726

Medium priority
Needs evaluation

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81725

Medium priority
Needs evaluation

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags....

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81724

Medium priority
Needs evaluation

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input....

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81723

Medium priority
Needs evaluation

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81722

Medium priority
Needs evaluation

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y'...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-78002

Medium priority
Needs evaluation

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect...

1 affected package

rsyslog

Package 24.04 LTS
rsyslog Needs evaluation
Show less packages

CVE-2026-59280

Medium priority
Needs evaluation

Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through...

1 affected package

libspring-java

Package 24.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-5680

Medium priority
Needs evaluation

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the...

1 affected package

undertow

Package 24.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-47893

Medium priority
Needs evaluation

A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 -...

1 affected package

libspring-java

Package 24.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-47892

Medium priority
Needs evaluation

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring...

1 affected package

libspring-java

Package 24.04 LTS
libspring-java Needs evaluation
Show less packages