Search CVE reports


Toggle filters

1311 – 1320 of 38256 results

Status is adjusted based on your filters.


CVE-2026-68497

Medium priority
Needs evaluation

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in...

1 affected package

jackson-databind

Package 26.04 LTS
jackson-databind Needs evaluation
Show less packages

CVE-2026-87020

Medium priority
Needs evaluation

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

1 affected package

orthanc

Package 26.04 LTS
orthanc Needs evaluation
Show less packages

CVE-2026-85979

Medium priority
Needs evaluation

Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell...

1 affected package

puppetserver

Package 26.04 LTS
puppetserver Needs evaluation
Show less packages

CVE-2026-89259

Medium priority
Needs evaluation

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive...

1 affected package

hugo

Package 26.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-89258

Medium priority
Needs evaluation

Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place —...

1 affected package

hugo

Package 26.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-87776

Medium priority
Needs evaluation

compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never...

1 affected package

node-compression

Package 26.04 LTS
node-compression Needs evaluation
Show less packages

CVE-2026-89147

Medium priority
Needs evaluation

Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client...

1 affected package

net-snmp

Package 26.04 LTS
net-snmp Needs evaluation
Show less packages

CVE-2026-77159

Medium priority
Needs evaluation

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm...

2 affected packages

libvirt, libvirt-hwe

Package 26.04 LTS
libvirt Needs evaluation
libvirt-hwe Needs evaluation
Show less packages

CVE-2026-87859

Medium priority
Needs evaluation

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that...

1 affected package

node-morgan

Package 26.04 LTS
node-morgan Needs evaluation
Show less packages

CVE-2026-87908

Medium priority
Needs evaluation

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...

1 affected package

node-multiparty

Package 26.04 LTS
node-multiparty Needs evaluation
Show less packages