Search CVE reports


Toggle filters

3181 – 3190 of 35604 results

Status is adjusted based on your filters.


CVE-2026-0540

Medium priority
Needs evaluation

DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2025-15599

Medium priority
Needs evaluation

DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-22891

Medium priority
Needs evaluation

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution....

1 affected package

biosig

Package 24.04 LTS
biosig Needs evaluation
Show less packages

CVE-2026-20777

Medium priority
Needs evaluation

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An...

1 affected package

biosig

Package 24.04 LTS
biosig Needs evaluation
Show less packages

CVE-2025-64736

Medium priority
Needs evaluation

An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (5462afb0). A specially crafted .abf file can lead to an information leak. An attacker can provide...

1 affected package

biosig

Package 24.04 LTS
biosig Needs evaluation
Show less packages

CVE-2026-25674

Low priority
Needs evaluation

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created...

1 affected package

python-django

Package 24.04 LTS
python-django Needs evaluation
Show less packages

CVE-2026-25673

Medium priority
Not affected

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow...

1 affected package

python-django

Package 24.04 LTS
python-django Not affected
Show less packages

CVE-2026-3351

Medium priority

Not in release

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.

1 affected package

lxd

Package 24.04 LTS
lxd Not in release
Show less packages

CVE-2026-3196

Medium priority
Fixed

two potential OOB memory accesses in virtio-snd

1 affected package

qemu

Package 24.04 LTS
qemu Fixed
Show less packages

CVE-2026-3195

Medium priority
Fixed

two potential OOB memory accesses in virtio-snd

1 affected package

qemu

Package 24.04 LTS
qemu Fixed
Show less packages