Search CVE reports


Toggle filters

2031 – 2040 of 38256 results

Status is adjusted based on your filters.


CVE-2026-85044

Medium priority
Not affected

Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-85043

Medium priority
Not affected

Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-85042

Medium priority
Not affected

Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-85396

Medium priority
Needs evaluation

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries...

1 affected package

ruby-zip

Package 26.04 LTS
ruby-zip Needs evaluation
Show less packages

CVE-2026-85394

Medium priority

Not in release

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens...

1 affected package

python-jose

Package 26.04 LTS
python-jose Not in release
Show less packages

CVE-2026-85393

Medium priority

Not in release

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid...

1 affected package

node-node-forge

Package 26.04 LTS
node-node-forge Not in release
Show less packages

CVE-2026-33630

Medium priority
Needs evaluation

c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the...

1 affected package

c-ares

Package 26.04 LTS
c-ares Needs evaluation
Show less packages

CVE-2026-84968

Medium priority
Needs evaluation

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message...

1 affected package

php-mongodb

Package 26.04 LTS
php-mongodb Needs evaluation
Show less packages

CVE-2026-84966

Medium priority

Not in release

An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field...

1 affected package

mongo-cxx-driver

Package 26.04 LTS
mongo-cxx-driver Not in release
Show less packages

CVE-2026-84965

Medium priority
Needs evaluation

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are...

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages