Search CVE reports


Toggle filters

101 – 110 of 36989 results

Status is adjusted based on your filters.


CVE-2025-68458

Medium priority
Needs evaluation

Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using...

1 affected package

node-webpack

Package 20.04 LTS
node-webpack Needs evaluation
Show less packages

CVE-2025-68157

Medium priority
Needs evaluation

Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate...

1 affected package

node-webpack

Package 20.04 LTS
node-webpack Needs evaluation
Show less packages

CVE-2025-68121

Medium priority
Needs evaluation

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed....

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 20.04 LTS
golang
golang-1.6
golang-1.8
golang-1.9
golang-1.10
golang-1.13 Needs evaluation
golang-1.14 Needs evaluation
golang-1.16 Needs evaluation
golang-1.17
golang-1.18 Needs evaluation
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2025-58190

Medium priority
Needs evaluation

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 20.04 LTS
golang-golang-x-net
google-guest-agent Not affected
containerd Not affected
golang-golang-x-net-dev Needs evaluation
adsys Not affected
juju-core
lxd Needs evaluation
Show all 7 packages Show less packages

CVE-2025-47911

Medium priority
Needs evaluation

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 20.04 LTS
golang-golang-x-net
google-guest-agent Not affected
containerd Not affected
golang-golang-x-net-dev Needs evaluation
adsys Not affected
juju-core
lxd Needs evaluation
Show all 7 packages Show less packages

CVE-2020-37127

Low priority
Fixed

Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the...

1 affected package

dnsmasq

Package 20.04 LTS
dnsmasq Fixed
Show less packages

CVE-2020-37121

Medium priority
Needs evaluation

CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious M3U playlist...

1 affected package

codeblocks

Package 20.04 LTS
codeblocks Needs evaluation
Show less packages

CVE-2025-61732

Medium priority
Needs evaluation

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

7 affected packages

golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...

Package 20.04 LTS
golang-1.17
golang-1.20 Needs evaluation
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23
golang-1.24
golang-1.25
Show all 7 packages Show less packages

CVE-2025-22873

Medium priority

Not in release

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent...

2 affected packages

golang-1.23, golang-1.24

Package 20.04 LTS
golang-1.23 Not in release
golang-1.24 Not in release
Show less packages

CVE-2026-25547

Medium priority
Needs evaluation

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an...

1 affected package

node-brace-expansion

Package 20.04 LTS
node-brace-expansion Needs evaluation
Show less packages