Search CVE reports


Toggle filters

1611 – 1620 of 58108 results

Status is adjusted based on your filters.


CVE-2026-84366

Medium priority
Needs evaluation

Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Needs evaluation
python3.4
python3.5 Needs evaluation
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.14
Show all 11 packages Show less packages

CVE-2026-84361

Medium priority
Needs evaluation

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and...

1 affected package

composer

Package 16.04 LTS
composer Needs evaluation
Show less packages

CVE-2026-84311

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of...

2 affected packages

pypdf, pypdf2

Package 16.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-84310

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document...

2 affected packages

pypdf, pypdf2

Package 16.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-63435

Medium priority
Needs evaluation

Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match and an overly greedy...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 16.04 LTS
ruby2.3 Needs evaluation
ruby2.5
ruby2.7
ruby3.0
ruby3.2
ruby3.3
jruby Needs evaluation
Show all 7 packages Show less packages

CVE-2026-84308

Medium priority
Needs evaluation

phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and...

3 affected packages

phpseclib, php-phpseclib, php-phpseclib3

Package 16.04 LTS
phpseclib Needs evaluation
php-phpseclib Needs evaluation
php-phpseclib3
Show less packages

CVE-2026-84305

Medium priority
Needs evaluation

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in...

1 affected package

sqlparse

Package 16.04 LTS
sqlparse Needs evaluation
Show less packages

CVE-2026-84304

Medium priority
Needs evaluation

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume...

3 affected packages

golang-google-grpc, google-guest-agent, grpc

Package 16.04 LTS
golang-google-grpc Needs evaluation
google-guest-agent Needs evaluation
grpc Needs evaluation
Show less packages

CVE-2026-84303

Medium priority
Needs evaluation

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata...

3 affected packages

golang-google-grpc, google-guest-agent, grpc

Package 16.04 LTS
golang-google-grpc Needs evaluation
google-guest-agent Needs evaluation
grpc Needs evaluation
Show less packages

CVE-2026-52295

Medium priority
Needs evaluation

FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.

2 affected packages

ffmpeg, libav

Package 16.04 LTS
ffmpeg Needs evaluation
libav
Show less packages