Search CVE reports


Toggle filters

41 – 50 of 47458 results

Status is adjusted based on your filters.


CVE-2026-2048

Medium priority
Needs evaluation

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-2047

Medium priority
Needs evaluation

GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-2045

Medium priority
Needs evaluation

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-2044

Medium priority
Needs evaluation

GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-0797

Medium priority
Needs evaluation

GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...

1 affected package

gimp

Package 16.04 LTS
gimp Needs evaluation
Show less packages

CVE-2019-25452

Medium priority
Needs evaluation

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST...

1 affected package

dolibarr

Package 16.04 LTS
dolibarr Needs evaluation
Show less packages

CVE-2019-25450

Medium priority
Needs evaluation

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through...

1 affected package

dolibarr

Package 16.04 LTS
dolibarr Needs evaluation
Show less packages

CVE-2026-27475

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27474

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-27473

Medium priority
Needs evaluation

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages