Search CVE reports


Toggle filters

681 – 690 of 46447 results

Status is adjusted based on your filters.


CVE-2026-7260

Medium priority
Needs evaluation

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 22.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Not in release
php7.4 Not in release
php8.1 Needs evaluation
php8.3 Not in release
php8.5 Not in release
Show all 7 packages Show less packages

CVE-2026-17544

Medium priority
Not affected

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 22.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Not in release
php7.4 Not in release
php8.1 Not affected
php8.3 Not in release
php8.5 Not in release
Show all 7 packages Show less packages

CVE-2026-17543

Medium priority
Needs evaluation

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 22.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Not in release
php7.4 Not in release
php8.1 Needs evaluation
php8.3 Not in release
php8.5 Not in release
Show all 7 packages Show less packages

CVE-2026-18369

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address....

1 affected package

dogtag-pki

Package 22.04 LTS
dogtag-pki Needs evaluation
Show less packages

CVE-2022-4994

Medium priority
Vulnerable

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pio_in() now that...

163 affected packages

linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...

Package 22.04 LTS
linux Vulnerable
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Not in release
linux-hwe-5.11 Not in release
linux-hwe-5.13 Not in release
linux-hwe-5.15 Not in release
linux-hwe-5.19 Ignored
linux-hwe-6.2 Ignored
linux-hwe-6.5 Ignored
linux-hwe-6.8 Not affected
linux-hwe-6.11 Not in release
linux-hwe-6.14 Not in release
linux-hwe-6.17 Not in release
linux-hwe-7.0 Not in release
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Vulnerable
linux-allwinner-5.19 Ignored
linux-aws Vulnerable
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws-5.8 Not in release
linux-aws-5.11 Not in release
linux-aws-5.13 Not in release
linux-aws-5.15 Not in release
linux-aws-5.19 Ignored
linux-aws-6.2 Ignored
linux-aws-6.5 Ignored
linux-aws-6.8 Not affected
linux-aws-6.14 Not in release
linux-aws-6.17 Not in release
linux-aws-hwe Not in release
linux-azure Vulnerable
linux-azure-4.15 Not in release
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Not in release
linux-azure-5.11 Not in release
linux-azure-5.13 Not in release
linux-azure-5.15 Not in release
linux-azure-5.19 Ignored
linux-azure-6.2 Ignored
linux-azure-6.5 Ignored
linux-azure-6.8 Not affected
linux-azure-6.11 Not in release
linux-azure-6.14 Not in release
linux-azure-6.17 Not in release
linux-azure-fde Vulnerable
linux-azure-fde-5.15 Not in release
linux-azure-fde-5.19 Ignored
linux-azure-fde-6.2 Ignored
linux-azure-fde-6.8 Not affected
linux-azure-fde-6.14 Not in release
linux-azure-fde-6.17 Not in release
linux-azure-nvidia Not in release
linux-azure-nvidia-6.14 Not in release
linux-bluefield Not in release
linux-azure-edge Not in release
linux-fips Vulnerable
linux-aws-fips Vulnerable
linux-azure-fips Vulnerable
linux-gcp-fips Vulnerable
linux-gcp Vulnerable
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Not in release
linux-gcp-5.11 Not in release
linux-gcp-5.13 Not in release
linux-gcp-5.15 Not in release
linux-gcp-5.19 Ignored
linux-gcp-6.2 Ignored
linux-gcp-6.5 Ignored
linux-gcp-6.8 Not affected
linux-gcp-6.11 Not in release
linux-gcp-6.14 Not in release
linux-gcp-6.17 Not in release
linux-gke Vulnerable
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Not in release
linux-gkeop Vulnerable
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Not in release
linux-ibm Vulnerable
linux-ibm-5.4 Not in release
linux-ibm-5.15 Not in release
linux-ibm-6.8 Not affected
linux-intel-5.13 Not in release
linux-intel-iotg Vulnerable
linux-intel-iotg-5.15 Not in release
linux-iot Not in release
linux-intel-iot-realtime Vulnerable
linux-lowlatency Vulnerable
linux-lowlatency-hwe-5.15 Not in release
linux-lowlatency-hwe-5.19 Ignored
linux-lowlatency-hwe-6.2 Ignored
linux-lowlatency-hwe-6.5 Ignored
linux-lowlatency-hwe-6.8 Not affected
linux-lowlatency-hwe-6.11 Not in release
linux-nvidia Vulnerable
linux-nvidia-6.2 Ignored
linux-nvidia-6.5 Ignored
linux-nvidia-6.8 Not affected
linux-nvidia-6.11 Not in release
linux-nvidia-6.17 Not in release
linux-nvidia-7.0 Not in release
linux-nvidia-bos Not in release
linux-nvidia-lowlatency Not in release
linux-nvidia-tegra Vulnerable
linux-nvidia-tegra-5.15 Not in release
linux-nvidia-tegra-igx Vulnerable
linux-oracle Vulnerable
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Not in release
linux-oracle-5.11 Not in release
linux-oracle-5.13 Not in release
linux-oracle-5.15 Not in release
linux-oracle-6.5 Ignored
linux-oracle-6.8 Not affected
linux-oracle-6.14 Not in release
linux-oracle-6.17 Not in release
linux-oem Not in release
linux-oem-5.6 Not in release
linux-oem-5.10 Not in release
linux-oem-5.13 Not in release
linux-oem-5.14 Not in release
linux-oem-5.17 Ignored
linux-oem-6.0 Ignored
linux-oem-6.1 Ignored
linux-oem-6.5 Ignored
linux-oem-6.8 Not in release
linux-oem-6.11 Not in release
linux-oem-6.14 Not in release
linux-oem-6.17 Not in release
linux-oem-7.0 Not in release
linux-raspi Vulnerable
linux-raspi2 Not in release
linux-raspi-5.4 Not in release
linux-raspi-realtime Not in release
linux-realtime Vulnerable
linux-realtime-6.8 Not affected
linux-realtime-6.14 Not in release
linux-riscv Ignored
linux-riscv-5.8 Not in release
linux-riscv-5.11 Not in release
linux-riscv-5.15 Not in release
linux-riscv-5.19 Ignored
linux-riscv-6.5 Ignored
linux-riscv-6.8 Not affected
linux-riscv-6.14 Not in release
linux-riscv-6.17 Not in release
linux-starfive-5.19 Ignored
linux-starfive-6.2 Ignored
linux-starfive-6.5 Ignored
linux-xilinx Not in release
linux-xilinx-zynqmp Vulnerable
linux-realtime-6.17 Not in release
linux-aws-7.0 Not in release
Show all 163 packages Show less packages

CVE-2026-58043

Medium priority
Needs evaluation

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or...

1 affected package

nodejs

Package 22.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-58040

Medium priority
Needs evaluation

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

1 affected package

nodejs

Package 22.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-56850

Medium priority
Needs evaluation

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability...

1 affected package

nodejs

Package 22.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-56847

Medium priority
Needs evaluation

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under...

1 affected package

nodejs

Package 22.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-16531

Medium priority
Needs evaluation

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

1 affected package

pcp

Package 22.04 LTS
pcp Needs evaluation
Show less packages