Search CVE reports


Toggle filters

201 – 210 of 45011 results

Status is adjusted based on your filters.


CVE-2026-48813

Medium priority
Needs evaluation

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI...

1 affected package

flawfinder

Package 20.04 LTS
flawfinder Needs evaluation
Show less packages

CVE-2026-48809

Medium priority
Needs evaluation

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked...

1 affected package

python-engineio

Package 20.04 LTS
python-engineio Needs evaluation
Show less packages

CVE-2026-48804

Medium priority
Needs evaluation

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the...

1 affected package

python-socketio

Package 20.04 LTS
python-socketio Needs evaluation
Show less packages

CVE-2026-48802

Medium priority
Needs evaluation

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the...

1 affected package

python-engineio

Package 20.04 LTS
python-engineio Needs evaluation
Show less packages

CVE-2026-48554

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command...

1 affected package

nagios4

Package 20.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48553

Medium priority
Needs evaluation

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a...

1 affected package

nagios4

Package 20.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48552

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization,...

1 affected package

nagios4

Package 20.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48551

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass...

1 affected package

nagios4

Package 20.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48550

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by...

1 affected package

nagios4

Package 20.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-29036

Medium priority
Needs evaluation

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations...

1 affected package

cjson

Package 20.04 LTS
cjson Needs evaluation
Show less packages