Search CVE reports


Toggle filters

21 – 30 of 32959 results

Status is adjusted based on your filters.


CVE-2026-64677

Medium priority

Not in release

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or...

1 affected package

anki

Package 26.04 LTS
anki Not in release
Show less packages

CVE-2026-64655

Medium priority
Needs evaluation

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow  flag values without...

1 affected package

gh

Package 26.04 LTS
gh Needs evaluation
Show less packages

CVE-2026-64654

Medium priority
Needs evaluation

GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content...

1 affected package

gh

Package 26.04 LTS
gh Needs evaluation
Show less packages

CVE-2026-64653

Medium priority
Needs evaluation

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or...

1 affected package

gh

Package 26.04 LTS
gh Needs evaluation
Show less packages

CVE-2026-64652

Medium priority
Needs evaluation

GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As...

1 affected package

gh

Package 26.04 LTS
gh Needs evaluation
Show less packages

CVE-2026-64638

Medium priority
Needs evaluation

[Unknown description]

1 affected package

wordpress

Package 26.04 LTS
wordpress Needs evaluation
Show less packages

CVE-2026-61632

Medium priority
Needs evaluation

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...

2 affected packages

markdown, python-markdown

Package 26.04 LTS
markdown Needs evaluation
python-markdown Needs evaluation
Show less packages

CVE-2026-61477

Medium priority
Needs evaluation

[Unknown description]

1 affected package

libvirt

Package 26.04 LTS
libvirt Needs evaluation
Show less packages

CVE-2026-52682

Medium priority
Needs evaluation

[A crafted DNS packet can cause increased memory and CPU consumption]

3 affected packages

dnsdist, pdns, pdns-recursor

Package 26.04 LTS
dnsdist Needs evaluation
pdns Needs evaluation
pdns-recursor Needs evaluation
Show less packages

CVE-2026-50159

Medium priority

Not in release

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated...

1 affected package

node-mermaid

Package 26.04 LTS
node-mermaid Not in release
Show less packages