Search CVE reports


Toggle filters

1 – 10 of 41351 results

Status is adjusted based on your filters.


CVE-2026-1801

Medium priority
Needs evaluation

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk...

2 affected packages

libsoup2.4, libsoup3

Package 18.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2026-25241

Medium priority
Needs evaluation

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows remote attackers to execute arbitrary SQL via a...

1 affected package

php-pear

Package 18.04 LTS
php-pear Needs evaluation
Show less packages

CVE-2026-25240

Medium priority
Needs evaluation

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are provided as an array and interpolated into an IN...

1 affected package

php-pear

Package 18.04 LTS
php-pear Needs evaluation
Show less packages

CVE-2026-25239

Medium priority
Needs evaluation

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue insertion can allow query manipulation if an attacker can influence the inserted...

1 affected package

php-pear

Package 18.04 LTS
php-pear Needs evaluation
Show less packages

CVE-2026-25238

Medium priority
Needs evaluation

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. This issue...

1 affected package

php-pear

Package 18.04 LTS
php-pear Needs evaluation
Show less packages

CVE-2026-25237

Medium priority
Needs evaluation

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable PHP code execution if attacker-controlled content...

1 affected package

php-pear

Package 18.04 LTS
php-pear Needs evaluation
Show less packages

CVE-2026-25236

Medium priority
Needs evaluation

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution for an IN (...) list. This issue has been patched in...

1 affected package

php-pear

Package 18.04 LTS
php-pear Needs evaluation
Show less packages

CVE-2026-25235

Medium priority
Needs evaluation

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens and potentially verify election account requests...

1 affected package

php-pear

Package 18.04 LTS
php-pear Needs evaluation
Show less packages

CVE-2026-25234

Medium priority
Needs evaluation

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with access to the category manager workflow to inject SQL...

1 affected package

php-pear

Package 18.04 LTS
php-pear Needs evaluation
Show less packages

CVE-2026-25233

Medium priority
Needs evaluation

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, or delete roadmaps. This issue has been patched...

1 affected package

php-pear

Package 18.04 LTS
php-pear Needs evaluation
Show less packages