Search CVE reports


Toggle filters

341 – 350 of 59781 results

Status is adjusted based on your filters.


CVE-2026-17545

Medium priority
Needs evaluation

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5 —
php7.0 Needs evaluation
php7.2 —
php7.4 —
php8.1 —
php8.3 —
php8.5 —
Show all 7 packages Show less packages

CVE-2025-14181

Medium priority
Needs evaluation

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5 —
php7.0 Needs evaluation
php7.2 —
php7.4 —
php8.1 —
php8.3 —
php8.5 —
Show all 7 packages Show less packages

CVE-2025-1218

Medium priority
Needs evaluation

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5 —
php7.0 Needs evaluation
php7.2 —
php7.4 —
php8.1 —
php8.3 —
php8.5 —
Show all 7 packages Show less packages

CVE-2026-93682

Medium priority
Needs evaluation

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5 —
php7.0 Needs evaluation
php7.2 —
php7.4 —
php8.1 —
php8.3 —
php8.5 —
Show all 7 packages Show less packages

CVE-2026-100310

Medium priority
Needs evaluation

GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX...

1 affected package

libextractor

Package 16.04 LTS
libextractor Needs evaluation
Show less packages

CVE-2026-55217

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the...

1 affected package

glpi

Package 16.04 LTS
glpi Needs evaluation
Show less packages

CVE-2026-55214

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the...

1 affected package

glpi

Package 16.04 LTS
glpi Needs evaluation
Show less packages

CVE-2026-53629

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a...

1 affected package

glpi

Package 16.04 LTS
glpi Needs evaluation
Show less packages

CVE-2026-53628

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable...

1 affected package

glpi

Package 16.04 LTS
glpi Needs evaluation
Show less packages

CVE-2026-53627

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform...

1 affected package

glpi

Package 16.04 LTS
glpi Needs evaluation
Show less packages