Search CVE reports


Toggle filters

21 – 30 of 36956 results

Status is adjusted based on your filters.


CVE-2026-4645

Medium priority
Needs evaluation

A flaw was found in the `github.com/antchfx/xpath` component. A remote attacker could exploit this vulnerability by submitting crafted Boolean XPath expressions that evaluate to true. This can cause an infinite loop in the...

2 affected packages

golang-github-antchfx-xpath, golang-golang-x-vuln

Package 22.04 LTS
golang-github-antchfx-xpath Needs evaluation
golang-golang-x-vuln Not in release
Show less packages

CVE-2026-25075

Medium priority
Fixed

strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid...

1 affected package

strongswan

Package 22.04 LTS
strongswan Fixed
Show less packages

CVE-2026-23555

Medium priority
Needs evaluation

Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenstored when verifying the node path. Note that the crash is forced...

1 affected package

xen

Package 22.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-23554

Medium priority
Needs evaluation

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush. Freeing of paging...

1 affected package

xen

Package 22.04 LTS
xen Needs evaluation
Show less packages

CVE-2019-25591

Medium priority
Needs evaluation

DNSS Domain Name Search Software 2.1.8 contains a buffer overflow vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can...

1 affected package

dnss

Package 22.04 LTS
dnss Needs evaluation
Show less packages

CVE-2026-4115

Medium priority
Needs evaluation

A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic...

1 affected package

putty

Package 22.04 LTS
putty Needs evaluation
Show less packages

CVE-2026-4541

Medium priority
Needs evaluation

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes...

1 affected package

tinyssh

Package 22.04 LTS
tinyssh Needs evaluation
Show less packages

CVE-2026-4539

Medium priority
Needs evaluation

A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity....

1 affected package

pygments

Package 22.04 LTS
pygments Needs evaluation
Show less packages

CVE-2026-4538

Medium priority
Needs evaluation

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a...

1 affected package

pytorch

Package 22.04 LTS
pytorch Needs evaluation
Show less packages

CVE-2026-33550

Medium priority
Needs evaluation

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).

1 affected package

sogo

Package 22.04 LTS
sogo Needs evaluation
Show less packages