Search CVE reports


Toggle filters

101 – 110 of 46017 results

Status is adjusted based on your filters.


CVE-2026-59894

Medium priority
Needs evaluation

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the...

1 affected package

sqlparse

Package 20.04 LTS
sqlparse Needs evaluation
Show less packages

CVE-2026-59893

Medium priority
Needs evaluation

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment...

1 affected package

sqlparse

Package 20.04 LTS
sqlparse Needs evaluation
Show less packages

CVE-2026-54284

Medium priority
Needs evaluation

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case,...

1 affected package

sqlparse

Package 20.04 LTS
sqlparse Needs evaluation
Show less packages

CVE-2026-68518

Medium priority
Needs evaluation

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache...

1 affected package

glances

Package 20.04 LTS
glances Needs evaluation
Show less packages

CVE-2026-68517

Medium priority
Needs evaluation

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin...

1 affected package

glances

Package 20.04 LTS
glances Needs evaluation
Show less packages

CVE-2026-61666

Medium priority
Needs evaluation

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError,...

1 affected package

ruby-websocket-driver

Package 20.04 LTS
ruby-websocket-driver Needs evaluation
Show less packages

CVE-2026-73646

Medium priority
Needs evaluation

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values...

1 affected package

node-postcss

Package 20.04 LTS
node-postcss Needs evaluation
Show less packages

CVE-2026-75010

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only...

1 affected package

roundcube

Package 20.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-75007

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

1 affected package

roundcube

Package 20.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-75006

Medium priority
Needs evaluation

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network...

1 affected package

roundcube

Package 20.04 LTS
roundcube Needs evaluation
Show less packages