Search CVE reports


Toggle filters

1771 – 1780 of 26561 results

Status is adjusted based on your filters.


CVE-2026-30656

Medium priority
Needs evaluation

A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup()...

1 affected package

fio

Package 26.04 LTS
fio Needs evaluation
Show less packages

CVE-2026-41015

Medium priority
Needs evaluation

radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for...

1 affected package

radare2

Package 26.04 LTS
radare2 Needs evaluation
Show less packages

CVE-2026-40962

Medium priority
Needs evaluation

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

2 affected packages

ffmpeg, libav

Package 26.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-40505

Medium priority
Needs evaluation

MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in...

1 affected package

mupdf

Package 26.04 LTS
mupdf Needs evaluation
Show less packages

CVE-2026-41035

Low priority
Vulnerable

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all)...

1 affected package

rsync

Package 26.04 LTS
rsync Vulnerable
Show less packages

CVE-2026-40960

Medium priority
Needs evaluation

Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure...

1 affected package

luanti

Package 26.04 LTS
luanti Needs evaluation
Show less packages

CVE-2026-40959

Medium priority
Needs evaluation

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

1 affected package

luanti

Package 26.04 LTS
luanti Needs evaluation
Show less packages

CVE-2026-35469

Medium priority
Needs evaluation

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation...

1 affected package

golang-github-docker-spdystream

Package 26.04 LTS
golang-github-docker-spdystream Needs evaluation
Show less packages

CVE-2026-40179

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where...

1 affected package

prometheus

Package 26.04 LTS
prometheus Needs evaluation
Show less packages

CVE-2026-40261

Medium priority
Needs evaluation

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell...

1 affected package

composer

Package 26.04 LTS
composer Needs evaluation
Show less packages