Search CVE reports


Toggle filters

231 – 240 of 36677 results

Status is adjusted based on your filters.


CVE-2026-27624

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed...

1 affected package

coturn

Package 22.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-3147

Medium priority
Needs evaluation

A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local...

1 affected package

vips

Package 22.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3146

Medium priority
Needs evaluation

A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack...

1 affected package

vips

Package 22.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3145

Medium priority
Needs evaluation

A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. Executing a manipulation can lead to...

1 affected package

vips

Package 22.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-27628

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2....

2 affected packages

pypdf, pypdf2

Package 22.04 LTS
pypdf Not in release
pypdf2 Needs evaluation
Show less packages

CVE-2026-27606

Medium priority
Needs evaluation

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal....

1 affected package

node-rollup

Package 22.04 LTS
node-rollup Needs evaluation
Show less packages

CVE-2026-3099

Low priority
Vulnerable

Broken Authentication: Digest Nonce Replay via Missing Nonce-Count Enforcement

2 affected packages

libsoup2.4, libsoup3

Package 22.04 LTS
libsoup2.4 Vulnerable
libsoup3 Vulnerable
Show less packages

CVE-2026-27572

Medium priority

Not in release

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the...

1 affected package

rust-wasmtime

Package 22.04 LTS
rust-wasmtime Not in release
Show less packages

CVE-2026-27204

Medium priority

Not in release

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime...

1 affected package

rust-wasmtime

Package 22.04 LTS
rust-wasmtime Not in release
Show less packages

CVE-2026-27195

Medium priority

Not in release

Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the default, which brought with it a new implementation of `[Typed]Func::call_async` which made it capable of calling...

1 affected package

rust-wasmtime

Package 22.04 LTS
rust-wasmtime Not in release
Show less packages