Search CVE reports


Toggle filters

1 – 10 of 31945 results

Status is adjusted based on your filters.


CVE-2026-26079

Medium priority
Needs evaluation

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-25531

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

kanboard-cli, python-kanboard

Package 24.04 LTS
kanboard-cli Needs evaluation
python-kanboard Needs evaluation
Show less packages

CVE-2026-2361

High priority
Needs evaluation

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then...

8 affected packages

postgresql-18, postgresql-17, postgresql-16, postgresql-14, postgresql-12...

Package 24.04 LTS
postgresql-18 Not in release
postgresql-17 Not in release
postgresql-16 Needs evaluation
postgresql-14 Not in release
postgresql-12 Not in release
postgresql-10 Not in release
postgresql-9.5 Not in release
postgresql-9.3 Not in release
Show all 8 packages Show less packages

CVE-2026-2239

Medium priority
Needs evaluation

[PSD loader: heap-buffer-overflow in fread_pascal_string() (no null terminator)]

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-1837

High priority
Needs evaluation

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by...

1 affected package

graphicsmagick

Package 24.04 LTS
graphicsmagick Needs evaluation
Show less packages

CVE-2026-1458

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS
gitlab Not in release
gitlab-agent Needs evaluation
Show less packages

CVE-2026-1456

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS
gitlab Not in release
gitlab-agent Needs evaluation
Show less packages

CVE-2026-1387

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS
gitlab Not in release
gitlab-agent Needs evaluation
Show less packages

CVE-2026-1282

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS
gitlab Not in release
gitlab-agent Needs evaluation
Show less packages

CVE-2026-1094

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS
gitlab Not in release
gitlab-agent Needs evaluation
Show less packages