Search CVE reports


Toggle filters

11 – 20 of 40142 results

Status is adjusted based on your filters.


CVE-2026-102578

Medium priority

Not in release

A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language)...

1 affected package

moodle

Package 26.04 LTS
moodle Not in release
Show less packages

CVE-2026-102577

Medium priority

Not in release

A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an...

1 affected package

moodle

Package 26.04 LTS
moodle Not in release
Show less packages

CVE-2026-103111

Medium priority
Needs evaluation

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

1 affected package

pcre2

Package 26.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-102805

Medium priority
Needs evaluation

A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation...

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-102804

Medium priority
Needs evaluation

A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument...

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-103051

Medium priority
Needs evaluation

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affects Mediawiki - CentralNotice...

1 affected package

mediawiki

Package 26.04 LTS
mediawiki Needs evaluation
Show less packages

CVE-2026-103050

Medium priority
Needs evaluation

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS. This issue affects Mediawiki - MassMessage...

1 affected package

mediawiki

Package 26.04 LTS
mediawiki Needs evaluation
Show less packages

CVE-2026-103048

Medium priority
Needs evaluation

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data. This issue affects Mediawiki - Collection extension: before 1.46.1,...

1 affected package

mediawiki

Package 26.04 LTS
mediawiki Needs evaluation
Show less packages

CVE-2026-66900

Medium priority
Needs evaluation

[hw/net/virtio-net: strip trailing padding when caching RSC segment]

2 affected packages

qemu, qemu-hwe

Package 26.04 LTS
qemu Needs evaluation
qemu-hwe Needs evaluation
Show less packages

CVE-2026-66899

Medium priority
Needs evaluation

[virtio-balloon: fix free-page BH teardown on unrealize]

2 affected packages

qemu, qemu-hwe

Package 26.04 LTS
qemu Needs evaluation
qemu-hwe Needs evaluation
Show less packages