Search CVE reports


Toggle filters

1 – 10 of 36922 results

Status is adjusted based on your filters.


CVE-2026-25731

Medium priority
Needs evaluation

calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom...

1 affected package

calibre

Package 20.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-25727

Medium priority
Needs evaluation

time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The...

1 affected package

rust-time

Package 20.04 LTS
rust-time Needs evaluation
Show less packages

CVE-2026-25636

Medium priority
Needs evaluation

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion,...

1 affected package

calibre

Package 20.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-25635

Medium priority
Needs evaluation

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this...

1 affected package

calibre

Package 20.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-25556

Medium priority
Needs evaluation

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer...

1 affected package

mupdf

Package 20.04 LTS
mupdf Needs evaluation
Show less packages

CVE-2026-23741

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on...

1 affected package

asterisk

Package 20.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2026-23740

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files to a directory that...

1 affected package

asterisk

Package 20.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2026-23739

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents using libxml with unsafe...

1 affected package

asterisk

Package 20.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2026-23738

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET variable query Parameter are...

1 affected package

asterisk

Package 20.04 LTS
asterisk Needs evaluation
Show less packages

CVE-2026-1998

Medium priority
Needs evaluation

A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mp_import_all of the file py/runtime.c. This manipulation causes memory corruption. The attack needs to be launched locally. The exploit...

1 affected package

micropython

Package 20.04 LTS
micropython Needs evaluation
Show less packages