Search CVE reports


Toggle filters

2291 – 2300 of 26183 results

Status is adjusted based on your filters.


CVE-2026-4437

Medium priority
Vulnerable

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server,...

2 affected packages

glibc, eglibc

Package 26.04 LTS
glibc Vulnerable
eglibc Not in release
Show less packages

CVE-2026-32710

Medium priority
Not affected

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might...

5 affected packages

mariadb, mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.6

Package 26.04 LTS
mariadb Not affected
mariadb-10.0 Not in release
mariadb-10.1 Not in release
mariadb-10.3 Not in release
mariadb-10.6 Not in release
Show less packages

CVE-2026-4519

Medium priority
Needs evaluation

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing...

14 affected packages

jython, pypy3, python2.7, python3.4, python3.5...

Package 26.04 LTS
jython Needs evaluation
pypy3 Needs evaluation
python2.7 Not in release
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Not in release
python3.11 Not in release
python3.12 Not in release
python3.13 Not in release
python3.14 Needs evaluation
Show all 14 packages Show less packages

CVE-2026-33123

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based...

1 affected package

pypdf

Package 26.04 LTS
pypdf Needs evaluation
Show less packages

CVE-2026-33069

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading out-of-bounds heap read in pjsip_multipart_parse(). After boundary string matching, curptr is advanced past...

1 affected package

pjproject

Package 26.04 LTS
pjproject Not in release
Show less packages

CVE-2026-33036

Medium priority
Needs evaluation

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and...

1 affected package

node-webfont

Package 26.04 LTS
node-webfont Needs evaluation
Show less packages

CVE-2026-32953

Medium priority
Needs evaluation

Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the tkeyclient Go module which causes 1 out of every 256 User Supplied Secrets (USS) to be silently ignored,...

1 affected package

golang-github-tillitis-tkeyclient

Package 26.04 LTS
golang-github-tillitis-tkeyclient Needs evaluation
Show less packages

CVE-2026-32945

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parser's name length handler. Thisimpacts applications using PJSIP's...

1 affected package

pjproject

Package 26.04 LTS
pjproject Not in release
Show less packages

CVE-2026-32942

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between...

1 affected package

pjproject

Package 26.04 LTS
pjproject Not in release
Show less packages

CVE-2026-32711

Medium priority
Needs evaluation

pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside the...

1 affected package

pydicom

Package 26.04 LTS
pydicom Needs evaluation
Show less packages