Search CVE reports


Toggle filters

181 – 190 of 40333 results

Status is adjusted based on your filters.


CVE-2026-102581

Medium priority

Not in release

A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then...

1 affected package

moodle

Package 26.04 LTS
moodle Not in release
Show less packages

CVE-2026-102580

Medium priority

Not in release

A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized...

1 affected package

moodle

Package 26.04 LTS
moodle Not in release
Show less packages

CVE-2026-102579

Medium priority

Not in release

A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to...

1 affected package

moodle

Package 26.04 LTS
moodle Not in release
Show less packages

CVE-2026-102578

Medium priority

Not in release

A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language)...

1 affected package

moodle

Package 26.04 LTS
moodle Not in release
Show less packages

CVE-2026-102577

Medium priority

Not in release

A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an...

1 affected package

moodle

Package 26.04 LTS
moodle Not in release
Show less packages

CVE-2026-103111

Medium priority
Needs evaluation

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

1 affected package

pcre2

Package 26.04 LTS
pcre2 Needs evaluation
Show less packages

CVE-2026-102805

Medium priority
Needs evaluation

A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation...

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-102804

Medium priority
Needs evaluation

A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument...

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-103051

Medium priority
Needs evaluation

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affects Mediawiki - CentralNotice...

1 affected package

mediawiki

Package 26.04 LTS
mediawiki Needs evaluation
Show less packages

CVE-2026-103050

Medium priority
Needs evaluation

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS. This issue affects Mediawiki - MassMessage...

1 affected package

mediawiki

Package 26.04 LTS
mediawiki Needs evaluation
Show less packages