Search CVE reports


Toggle filters

81 – 90 of 37641 results

Status is adjusted based on your filters.


CVE-2026-34378

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.4.0 to before 3.4.9, a missing bounds check on the dataWindow attribute in EXR...

1 affected package

openexr

Package 22.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-5663

Medium priority
Needs evaluation

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in...

1 affected package

dcmtk

Package 22.04 LTS
dcmtk Needs evaluation
Show less packages

CVE-2026-33540

Medium priority
Needs evaluation

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by...

1 affected package

docker-registry

Package 22.04 LTS
docker-registry Needs evaluation
Show less packages

CVE-2026-29047

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-26263

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-26027

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-26026

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-25932

Medium priority

Not in release

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-5673

Medium priority
Needs evaluation

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by...

4 affected packages

asc, libtheora, mkvtoolnix, ogmrip

Package 22.04 LTS
asc Needs evaluation
libtheora Needs evaluation
mkvtoolnix Needs evaluation
ogmrip Needs evaluation
Show less packages

CVE-2026-5266

Medium priority
Needs evaluation

[Unknown description]

1 affected package

mediawiki

Package 22.04 LTS
mediawiki Needs evaluation
Show less packages