Search CVE reports


Toggle filters

1911 – 1920 of 34841 results

Status is adjusted based on your filters.


CVE-2026-67422

Medium priority
Vulnerable

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups...

2 affected packages

markdown, pymdown-extensions

Package 26.04 LTS
markdown Not affected
pymdown-extensions Vulnerable
Show less packages

CVE-2026-64677

Medium priority

Not in release

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or...

1 affected package

anki

Package 26.04 LTS
anki Not in release
Show less packages

CVE-2026-64655

Medium priority
Needs evaluation

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow  flag values without...

1 affected package

gh

Package 26.04 LTS
gh Needs evaluation
Show less packages

CVE-2026-64654

Medium priority
Needs evaluation

GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content...

1 affected package

gh

Package 26.04 LTS
gh Needs evaluation
Show less packages

CVE-2026-64653

Medium priority
Needs evaluation

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or...

1 affected package

gh

Package 26.04 LTS
gh Needs evaluation
Show less packages

CVE-2026-64652

Medium priority
Needs evaluation

GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As...

1 affected package

gh

Package 26.04 LTS
gh Needs evaluation
Show less packages

CVE-2026-61632

Medium priority
Needs evaluation

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...

2 affected packages

markdown, python-markdown

Package 26.04 LTS
markdown Needs evaluation
python-markdown Needs evaluation
Show less packages

CVE-2026-50159

Medium priority

Not in release

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated...

1 affected package

node-mermaid

Package 26.04 LTS
node-mermaid Not in release
Show less packages

CVE-2026-43632

Medium priority
Needs evaluation

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens)...

1 affected package

llama.cpp

Package 26.04 LTS
llama.cpp Needs evaluation
Show less packages

CVE-2026-43631

Medium priority
Needs evaluation

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute...

1 affected package

llama.cpp

Package 26.04 LTS
llama.cpp Needs evaluation
Show less packages