Search CVE reports


Toggle filters

1971 – 1980 of 34607 results

Status is adjusted based on your filters.


CVE-2026-53505

Medium priority
Needs evaluation

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger...

1 affected package

thumbor

Package 26.04 LTS
thumbor Needs evaluation
Show less packages

CVE-2026-53504

Medium priority
Needs evaluation

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust...

1 affected package

thumbor

Package 26.04 LTS
thumbor Needs evaluation
Show less packages

CVE-2026-53503

Medium priority
Needs evaluation

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension...

1 affected package

thumbor

Package 26.04 LTS
thumbor Needs evaluation
Show less packages

CVE-2026-53502

Medium priority
Needs evaluation

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through...

1 affected package

thumbor

Package 26.04 LTS
thumbor Needs evaluation
Show less packages

CVE-2026-53501

Medium priority
Needs evaluation

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since...

1 affected package

thumbor

Package 26.04 LTS
thumbor Needs evaluation
Show less packages

CVE-2026-53500

Medium priority
Needs evaluation

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the...

1 affected package

thumbor

Package 26.04 LTS
thumbor Needs evaluation
Show less packages

CVE-2026-18321

Medium priority
Needs evaluation

Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd

1 affected package

ntpsec

Package 26.04 LTS
ntpsec Needs evaluation
Show less packages

CVE-2026-54707

Medium priority
Needs evaluation

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive...

1 affected package

onionshare

Package 26.04 LTS
onionshare Needs evaluation
Show less packages

CVE-2026-54706

Medium priority
Needs evaluation

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links...

1 affected package

onionshare

Package 26.04 LTS
onionshare Needs evaluation
Show less packages

CVE-2026-18446

Medium priority
Needs evaluation

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or...

1 affected package

node-ajv

Package 26.04 LTS
node-ajv Needs evaluation
Show less packages