Search CVE reports


Toggle filters

1681 – 1690 of 46017 results

Status is adjusted based on your filters.


CVE-2026-64677

Medium priority
Needs evaluation

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or...

1 affected package

anki

Package 20.04 LTS
anki Needs evaluation
Show less packages

CVE-2026-61632

Medium priority
Needs evaluation

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...

2 affected packages

markdown, python-markdown

Package 20.04 LTS
markdown Needs evaluation
python-markdown Needs evaluation
Show less packages

CVE-2026-18487

Medium priority
Needs evaluation

A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon...

1 affected package

epiphany-browser

Package 20.04 LTS
epiphany-browser Needs evaluation
Show less packages

CVE-2026-34502

Medium priority
Needs evaluation

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.

1 affected package

apr-util

Package 20.04 LTS
apr-util Needs evaluation
Show less packages

CVE-2026-34501

Medium priority
Needs evaluation

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes...

1 affected package

apr-util

Package 20.04 LTS
apr-util Needs evaluation
Show less packages

CVE-2026-34191

Medium priority
Needs evaluation

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

1 affected package

apr-util

Package 20.04 LTS
apr-util Needs evaluation
Show less packages

CVE-2026-32327

Medium priority
Needs evaluation

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses theĀ apr_xml_quote_elem() function. Users are recommended to upgrade to...

1 affected package

apr-util

Package 20.04 LTS
apr-util Needs evaluation
Show less packages

CVE-2025-49506

Medium priority
Needs evaluation

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on...

1 affected package

apr-util

Package 20.04 LTS
apr-util Needs evaluation
Show less packages

CVE-2026-18649

Medium priority
Needs evaluation

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A...

1 affected package

gst-plugins-good1.0

Package 20.04 LTS
gst-plugins-good1.0 Needs evaluation
Show less packages

CVE-2026-7867

Medium priority
Not affected

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the...

1 affected package

udisks2

Package 20.04 LTS
udisks2 Not affected
Show less packages