Search CVE reports


Toggle filters

1 – 10 of 37673 results

Status is adjusted based on your filters.


CVE-2026-4541

Medium priority
Needs evaluation

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes...

1 affected package

tinyssh

Package 20.04 LTS
tinyssh Needs evaluation
Show less packages

CVE-2026-4539

Medium priority
Needs evaluation

A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity....

1 affected package

pygments

Package 20.04 LTS
pygments Needs evaluation
Show less packages

CVE-2026-4115

Medium priority
Needs evaluation

A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic...

1 affected package

putty

Package 20.04 LTS
putty Needs evaluation
Show less packages

CVE-2026-33550

Medium priority
Needs evaluation

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).

1 affected package

sogo

Package 20.04 LTS
sogo Needs evaluation
Show less packages

CVE-2026-33549

Medium priority
Needs evaluation

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

1 affected package

spip

Package 20.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-33236

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-33231

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-33230

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-33228

Medium priority
Needs evaluation

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since...

1 affected package

node-flatted

Package 20.04 LTS
node-flatted Needs evaluation
Show less packages

CVE-2026-33210

Medium priority
Needs evaluation

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the...

1 affected package

ruby-json

Package 20.04 LTS
ruby-json Needs evaluation
Show less packages