Search CVE reports


Toggle filters

1 – 10 of 36937 results

Status is adjusted based on your filters.


CVE-2026-4541

Medium priority
Needs evaluation

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes...

1 affected package

tinyssh

Package 22.04 LTS
tinyssh Needs evaluation
Show less packages

CVE-2026-4539

Medium priority
Needs evaluation

A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity....

1 affected package

pygments

Package 22.04 LTS
pygments Needs evaluation
Show less packages

CVE-2026-4538

Medium priority
Needs evaluation

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a...

1 affected package

pytorch

Package 22.04 LTS
pytorch Needs evaluation
Show less packages

CVE-2026-4115

Medium priority
Needs evaluation

A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic...

1 affected package

putty

Package 22.04 LTS
putty Needs evaluation
Show less packages

CVE-2026-33550

Medium priority
Needs evaluation

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).

1 affected package

sogo

Package 22.04 LTS
sogo Needs evaluation
Show less packages

CVE-2026-33549

Medium priority
Needs evaluation

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

1 affected package

spip

Package 22.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-33236

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not...

1 affected package

nltk

Package 22.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-33231

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows...

1 affected package

nltk

Package 22.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-33230

Medium priority
Needs evaluation

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a...

1 affected package

nltk

Package 22.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-33228

Medium priority
Needs evaluation

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since...

1 affected package

node-flatted

Package 22.04 LTS
node-flatted Needs evaluation
Show less packages