Search CVE reports


Toggle filters

2231 – 2240 of 48458 results

Status is adjusted based on your filters.


CVE-2026-70626

Medium priority
Needs evaluation

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-68768

Medium priority
Needs evaluation

hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the...

1 affected package

hashcat

Package 20.04 LTS
hashcat Needs evaluation
Show less packages

CVE-2026-68767

Medium priority
Needs evaluation

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash...

1 affected package

hashcat

Package 20.04 LTS
hashcat Needs evaluation
Show less packages

CVE-2026-68766

Medium priority
Needs evaluation

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options...

1 affected package

hashcat

Package 20.04 LTS
hashcat Needs evaluation
Show less packages

CVE-2026-66393

Medium priority
Needs evaluation

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-65915

Medium priority
Needs evaluation

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file://...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-63312

Medium priority
Needs evaluation

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-63311

Medium priority
Needs evaluation

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-63310

Medium priority
Not affected

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

1 affected package

nltk

Package 20.04 LTS
nltk Not affected
Show less packages

CVE-2026-62388

Medium priority
Needs evaluation

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages