Search CVE reports


Toggle filters

2351 – 2360 of 39984 results

Status is adjusted based on your filters.


CVE-2026-4519

Medium priority
Needs evaluation

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing...

14 affected packages

jython, pypy3, python2.7, python3.4, python3.5...

Package 20.04 LTS
jython Needs evaluation
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Needs evaluation
python3.9 Needs evaluation
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 14 packages Show less packages

CVE-2026-32711

Medium priority
Needs evaluation

pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside the...

1 affected package

pydicom

Package 20.04 LTS
pydicom Needs evaluation
Show less packages

CVE-2026-22737

Medium priority
Needs evaluation

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This...

1 affected package

libspring-java

Package 20.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-22735

Medium priority
Needs evaluation

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25,...

1 affected package

libspring-java

Package 20.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-3842

Medium priority
Needs evaluation

[Unknown description]

1 affected package

qemu

Package 20.04 LTS
qemu Needs evaluation
Show less packages

CVE-2026-33056

Medium priority
Needs evaluation

tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a...

23 affected packages

rust-tar, rustc, rustc-1.62, rustc-1.74, rustc-1.76...

Package 20.04 LTS
rust-tar Needs evaluation
rustc Needs evaluation
rustc-1.62
rustc-1.74
rustc-1.76 Needs evaluation
rustc-1.77 Needs evaluation
rustc-1.78 Needs evaluation
rustc-1.79 Needs evaluation
rustc-1.80 Needs evaluation
rustc-1.81
rustc-1.82
rustc-1.83
rustc-1.84
rustc-1.85
rustc-1.88
rustc-1.89
rustc-1.91
rustc-1.92
rustc-1.93
cargo Needs evaluation
rust-cargo-c
rust-async-tar
rust-astral-tokio-tar
Show all 23 packages Show less packages

CVE-2026-33055

Medium priority
Needs evaluation

tar-rs is a tar archive reading/writing library for Rust. Versions 0.4.44 and below have conditional logic that skips the PAX size header in cases where the base header size is nonzero. As part of CVE-2025-62518,...

1 affected package

rust-tar

Package 20.04 LTS
rust-tar Needs evaluation
Show less packages

CVE-2026-32935

Medium priority
Needs evaluation

phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This...

3 affected packages

php-phpseclib, php-phpseclib3, phpseclib

Package 20.04 LTS
php-phpseclib Needs evaluation
php-phpseclib3
phpseclib Needs evaluation
Show less packages

CVE-2026-32875

Medium priority
Not affected

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handling. ujson.dumps() crashes the...

3 affected packages

collada2gltf, pandas, ujson

Package 20.04 LTS
collada2gltf
pandas Not affected
ujson Not affected
Show less packages

CVE-2026-32874

Medium priority
Not affected

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1])...

3 affected packages

collada2gltf, pandas, ujson

Package 20.04 LTS
collada2gltf
pandas Not affected
ujson Not affected
Show less packages