Search CVE reports


Toggle filters

31 – 40 of 52029 results

Status is adjusted based on your filters.


CVE-2026-61629

Medium priority
Needs evaluation

nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and...

1 affected package

nginx

Package 22.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-61628

Medium priority
Needs evaluation

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions....

1 affected package

nginx

Package 22.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-55567

Medium priority
Not affected

BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that...

1 affected package

bleachbit

Package 22.04 LTS
bleachbit Not affected
Show less packages

CVE-2016-15059

Medium priority
Not affected

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns,...

1 affected package

libnet-idn-encode-perl

Package 22.04 LTS
libnet-idn-encode-perl Not affected
Show less packages

CVE-2026-94108

Medium priority
Needs evaluation

getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media...

1 affected package

php-getid3

Package 22.04 LTS
php-getid3 Needs evaluation
Show less packages

CVE-2026-94106

Medium priority
Needs evaluation

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject...

1 affected package

php-getid3

Package 22.04 LTS
php-getid3 Needs evaluation
Show less packages

CVE-2026-94084

Medium priority
Needs evaluation

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-94083

Medium priority
Needs evaluation

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to...

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-94057

Medium priority
Needs evaluation

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

1 affected package

exim4

Package 22.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-94056

Medium priority
Needs evaluation

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

1 affected package

exim4

Package 22.04 LTS
exim4 Needs evaluation
Show less packages