Search CVE reports


Toggle filters

131 – 140 of 44355 results

Status is adjusted based on your filters.


CVE-2026-69192

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser,...

1 affected package

node-ip-address

Package 20.04 LTS
node-ip-address Needs evaluation
Show less packages

CVE-2026-69185

Medium priority
Needs evaluation

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer...

1 affected package

node-socket.io-parser

Package 20.04 LTS
node-socket.io-parser Needs evaluation
Show less packages

CVE-2026-69153

Medium priority
Needs evaluation

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an...

1 affected package

node-postcss

Package 20.04 LTS
node-postcss Needs evaluation
Show less packages

CVE-2026-69152

Medium priority
Needs evaluation

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or...

1 affected package

node-brace-expansion

Package 20.04 LTS
node-brace-expansion Needs evaluation
Show less packages

CVE-2026-69151

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and...

1 affected package

angular.js

Package 20.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2026-69149

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in...

1 affected package

angular.js

Package 20.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2026-68945

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters,...

1 affected package

angular.js

Package 20.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2026-18477

Medium priority
Needs evaluation

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has...

1 affected package

tar

Package 20.04 LTS
tar Needs evaluation
Show less packages

CVE-2026-18651

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked,...

1 affected package

389-ds-base

Package 20.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-18508

Medium priority
Needs evaluation

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A...

1 affected package

tar

Package 20.04 LTS
tar Needs evaluation
Show less packages