Search CVE reports


Toggle filters

91 – 100 of 40868 results

Status is adjusted based on your filters.


CVE-2026-45078

Medium priority
Needs evaluation

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied...

1 affected package

matrix-synapse

Package 22.04 LTS
matrix-synapse Needs evaluation
Show less packages

CVE-2026-45076

Medium priority
Needs evaluation

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients....

1 affected package

matrix-synapse

Package 22.04 LTS
matrix-synapse Needs evaluation
Show less packages

CVE-2026-44466

Medium priority
Needs evaluation

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nested inside an allowlisted command like echo. This...

1 affected package

zed

Package 22.04 LTS
zed Needs evaluation
Show less packages

CVE-2026-44465

Medium priority
Needs evaluation

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuration option. This allows an attacker to achieve Remote...

1 affected package

zed

Package 22.04 LTS
zed Needs evaluation
Show less packages

CVE-2026-44463

Medium priority
Needs evaluation

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary...

1 affected package

zed

Package 22.04 LTS
zed Needs evaluation
Show less packages

CVE-2026-44462

Medium priority
Needs evaluation

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowlisted command prefix. This...

1 affected package

zed

Package 22.04 LTS
zed Needs evaluation
Show less packages

CVE-2026-44461

Medium priority
Needs evaluation

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted without shell quoting or validation. If an attacker can...

1 affected package

zed

Package 22.04 LTS
zed Needs evaluation
Show less packages

CVE-2026-48735

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP metadata, possibly with lots of...

2 affected packages

pypdf, pypdf2

Package 22.04 LTS
pypdf Not in release
pypdf2 Needs evaluation
Show less packages

CVE-2026-48526

Medium priority
Needs evaluation

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC...

1 affected package

pyjwt

Package 22.04 LTS
pyjwt Needs evaluation
Show less packages

CVE-2026-48525

Medium priority
Needs evaluation

PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decoding of...

1 affected package

pyjwt

Package 22.04 LTS
pyjwt Needs evaluation
Show less packages