Search CVE reports


Toggle filters

1 – 10 of 1760 results


CVE-2026-13503

Medium priority
Needs evaluation

A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option...

1 affected package

antlr4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
antlr4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-13502

Medium priority
Needs evaluation

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin....

1 affected package

antlr4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
antlr4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-13501

Medium priority
Needs evaluation

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The...

1 affected package

antlr4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
antlr4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-13500

Medium priority
Needs evaluation

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation...

1 affected package

antlr4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
antlr4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-41196

Medium priority
Needs evaluation

Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and...

2 affected packages

luanti, minetest

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
luanti Needs evaluation Not in release Not in release
minetest Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40960

Medium priority
Fixed

Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure...

1 affected package

luanti

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
luanti Fixed Not in release Not in release
Show less packages

CVE-2026-40959

Medium priority
Fixed

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

1 affected package

luanti

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
luanti Fixed Not in release Not in release
Show less packages

CVE-2026-32287

Medium priority
Needs evaluation

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

1 affected package

golang-github-antchfx-xpath

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-antchfx-xpath Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-4645

Medium priority
Not affected

Rejected reason: Duplicate of CVE-2026-32287

2 affected packages

golang-github-antchfx-xpath, golang-golang-x-vuln

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-antchfx-xpath Not affected Not affected Not affected
golang-golang-x-vuln Not affected Not in release
Show less packages

CVE-2026-0858

Medium priority
Needs evaluation

Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can...

1 affected package

plantuml

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
plantuml Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages