Search CVE reports


Toggle filters

631 – 640 of 46439 results

Status is adjusted based on your filters.


CVE-2026-18446

Medium priority
Needs evaluation

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or...

1 affected package

node-ajv

Package 22.04 LTS
node-ajv Needs evaluation
Show less packages

CVE-2026-18358

Medium priority
Needs evaluation

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing...

1 affected package

gnome-remote-desktop

Package 22.04 LTS
gnome-remote-desktop Needs evaluation
Show less packages

CVE-2026-64607

Medium priority
Needs evaluation

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the...

2 affected packages

commons-httpclient, httpcomponents-client

Package 22.04 LTS
commons-httpclient Needs evaluation
httpcomponents-client Needs evaluation
Show less packages

CVE-2026-15722

Medium priority
Needs evaluation

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer...

1 affected package

389-ds-base

Package 22.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-11770

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against...

1 affected package

389-ds-base

Package 22.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-63223

Medium priority

Not in release

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content...

1 affected package

php-codeigniter-framework

Package 22.04 LTS
php-codeigniter-framework Not in release
Show less packages

CVE-2026-63222

Medium priority

Not in release

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal...

1 affected package

php-codeigniter-framework

Package 22.04 LTS
php-codeigniter-framework Not in release
Show less packages

CVE-2026-63221

Medium priority

Not in release

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled...

1 affected package

php-codeigniter-framework

Package 22.04 LTS
php-codeigniter-framework Not in release
Show less packages

CVE-2026-63220

Medium priority

Not in release

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these...

1 affected package

php-codeigniter-framework

Package 22.04 LTS
php-codeigniter-framework Not in release
Show less packages

CVE-2026-58039

Medium priority
Needs evaluation

A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected...

1 affected package

nodejs

Package 22.04 LTS
nodejs Needs evaluation
Show less packages