Search CVE reports


Toggle filters

11 – 20 of 59604 results

Status is adjusted based on your filters.


CVE-2026-102578

Medium priority
Needs evaluation

A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language)...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102577

Medium priority
Needs evaluation

A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-103111

Medium priority
Needs evaluation

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

1 affected package

pcre2

Package 16.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-17588

Medium priority
Needs evaluation

[hw/usb/hcd-xhci: Set reentrancy guard in timer functions]

2 affected packages

qemu, qemu-hwe

Package 16.04 LTS
qemu Needs evaluation
qemu-hwe —
Show less packages

CVE-2026-16271

Medium priority
Needs evaluation

[hw/display/qxl: validate primary surface stride against width]

2 affected packages

qemu, qemu-hwe

Package 16.04 LTS
qemu Needs evaluation
qemu-hwe —
Show less packages

CVE-2026-102621

Medium priority
Needs evaluation

A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed...

1 affected package

poppler

Package 16.04 LTS
poppler Needs evaluation
Show less packages

CVE-2026-102938

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with...

1 affected package

python-virtualenv

Package 16.04 LTS
python-virtualenv Needs evaluation
Show less packages

CVE-2026-102937

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker...

1 affected package

python-virtualenv

Package 16.04 LTS
python-virtualenv Needs evaluation
Show less packages

CVE-2026-102930

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes...

1 affected package

python-virtualenv

Package 16.04 LTS
python-virtualenv Needs evaluation
Show less packages

CVE-2026-102925

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted...

1 affected package

python-virtualenv

Package 16.04 LTS
python-virtualenv Needs evaluation
Show less packages