Search CVE reports


Toggle filters

891 – 900 of 41184 results

Status is adjusted based on your filters.


CVE-2026-41074

Medium priority
Needs evaluation

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious...

2 affected packages

request-tracker4, request-tracker5

Package 20.04 LTS
request-tracker4 Needs evaluation
request-tracker5
Show less packages

CVE-2026-41073

Medium priority
Needs evaluation

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is...

2 affected packages

request-tracker4, request-tracker5

Package 20.04 LTS
request-tracker4 Needs evaluation
request-tracker5
Show less packages

CVE-2026-41071

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes...

1 affected package

libheif

Package 20.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-41069

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have...

1 affected package

libheif

Package 20.04 LTS
libheif Needs evaluation
Show less packages

CVE-2026-40295

Medium priority
Needs evaluation

Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header,...

1 affected package

ruby-devise

Package 20.04 LTS
ruby-devise Needs evaluation
Show less packages

CVE-2026-39824

Medium priority
Needs evaluation

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

2 affected packages

golang-golang-x-sys, google-guest-agent

Package 20.04 LTS
golang-golang-x-sys Needs evaluation
google-guest-agent Needs evaluation
Show less packages

CVE-2026-48700

Medium priority
Needs evaluation

An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program...

1 affected package

pcmanfm-qt

Package 20.04 LTS
pcmanfm-qt Needs evaluation
Show less packages

CVE-2026-46727

Medium priority
Needs evaluation

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS...

7 affected packages

jruby, ruby2.3, ruby2.5, ruby2.7, ruby3.0...

Package 20.04 LTS
jruby Needs evaluation
ruby2.3
ruby2.5
ruby2.7 Needs evaluation
ruby3.0
ruby3.2
ruby3.3
Show all 7 packages Show less packages

CVE-2026-42506

Medium priority
Needs evaluation

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

1 affected package

golang-golang-x-net-dev

Package 20.04 LTS
golang-golang-x-net-dev Needs evaluation
Show less packages

CVE-2026-42502

Medium priority
Needs evaluation

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

1 affected package

golang-golang-x-net-dev

Package 20.04 LTS
golang-golang-x-net-dev Needs evaluation
Show less packages