Search CVE reports


Toggle filters

1 – 10 of 49194 results

Status is adjusted based on your filters.


CVE-2026-94108

Medium priority
Needs evaluation

getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media...

1 affected package

php-getid3

Package 20.04 LTS
php-getid3 Needs evaluation
Show less packages

CVE-2026-94106

Medium priority
Needs evaluation

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject...

1 affected package

php-getid3

Package 20.04 LTS
php-getid3 Needs evaluation
Show less packages

CVE-2026-94057

Medium priority
Needs evaluation

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

1 affected package

exim4

Package 20.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-94056

Medium priority
Needs evaluation

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

1 affected package

exim4

Package 20.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-94055

Medium priority
Needs evaluation

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

1 affected package

exim4

Package 20.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-94054

Medium priority
Needs evaluation

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

1 affected package

exim4

Package 20.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-93990

Medium priority
Needs evaluation

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume...

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 20.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Needs evaluation
cadaver Needs evaluation
gdcm Not affected
ayttm
cableswig
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk
smart
firefox
thunderbird
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-93987

Medium priority
Needs evaluation

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name)...

1 affected package

rclone

Package 20.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-93986

Medium priority
Needs evaluation

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and...

1 affected package

rclone

Package 20.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-93962

Medium priority
Needs evaluation

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation...

1 affected package

kamailio

Package 20.04 LTS
kamailio Needs evaluation
Show less packages