Search CVE reports


Toggle filters

201 – 210 of 35522 results

Status is adjusted based on your filters.


CVE-2026-42309

Medium priority
Needs evaluation

Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line...

2 affected packages

pillow, pillow-python2

Package 24.04 LTS
pillow Needs evaluation
pillow-python2 Not in release
Show less packages

CVE-2026-42307

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using...

1 affected package

vim

Package 24.04 LTS
vim Needs evaluation
Show less packages

CVE-2026-42258

Medium priority
Needs evaluation

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 24.04 LTS
ruby2.3 Not in release
ruby2.5 Not in release
ruby2.7 Not in release
ruby3.0 Not in release
ruby3.2 Needs evaluation
ruby3.3 Not in release
jruby Needs evaluation
Show all 7 packages Show less packages

CVE-2026-42257

Medium priority
Needs evaluation

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 24.04 LTS
ruby2.3 Not in release
ruby2.5 Not in release
ruby2.7 Not in release
ruby3.0 Not in release
ruby3.2 Needs evaluation
ruby3.3 Not in release
jruby Needs evaluation
Show all 7 packages Show less packages

CVE-2026-42256

Medium priority
Needs evaluation

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4, when authenticating a connection with SCRAM-SHA1...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 24.04 LTS
ruby2.3 Not in release
ruby2.5 Not in release
ruby2.7 Not in release
ruby3.0 Not in release
ruby3.2 Needs evaluation
ruby3.3 Not in release
jruby Needs evaluation
Show all 7 packages Show less packages

CVE-2026-42246

Medium priority
Needs evaluation

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully",...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 24.04 LTS
ruby2.3 Not in release
ruby2.5 Not in release
ruby2.7 Not in release
ruby3.0 Not in release
ruby3.2 Needs evaluation
ruby3.3 Not in release
jruby Needs evaluation
Show all 7 packages Show less packages

CVE-2026-42225

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_transport_tls) can accept connections with invalid or untrusted certificates even...

2 affected packages

asterisk, pjproject

Package 24.04 LTS
asterisk Needs evaluation
pjproject Not in release
Show less packages

CVE-2026-42150

Medium priority
Needs evaluation

wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc embeds API response data into HTML without escaping, allowing cross-site scripting when the output is rendered in...

1 affected package

wlc

Package 24.04 LTS
wlc Needs evaluation
Show less packages

CVE-2026-42030

Medium priority
Needs evaluation

MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker to inject arbitrary...

1 affected package

mapserver

Package 24.04 LTS
mapserver Needs evaluation
Show less packages

CVE-2026-41650

Medium priority
Needs evaluation

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the "]]>" sequence in...

1 affected package

node-webfont

Package 24.04 LTS
node-webfont Needs evaluation
Show less packages