Search CVE reports


Toggle filters

51 – 60 of 32830 results

Status is adjusted based on your filters.


CVE-2026-33154

Medium priority
Needs evaluation

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is...

1 affected package

python-dynaconf

Package 24.04 LTS
python-dynaconf Needs evaluation
Show less packages

CVE-2026-33150

Medium priority
Needs evaluation

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem...

2 affected packages

fuse, fuse3

Package 24.04 LTS
fuse Needs evaluation
fuse3 Needs evaluation
Show less packages

CVE-2026-33144

Medium priority
Needs evaluation

GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in...

1 affected package

gpac

Package 24.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-63261

Medium priority
Needs evaluation

AWStats 8.0 is vulnerable to Command Injection via the open function

1 affected package

awstats

Package 24.04 LTS
awstats Needs evaluation
Show less packages

CVE-2026-32710

Medium priority
Needs evaluation

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might...

1 affected package

mariadb

Package 24.04 LTS
mariadb Needs evaluation
Show less packages

CVE-2026-33123

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based...

1 affected package

pypdf

Package 24.04 LTS
pypdf Needs evaluation
Show less packages

CVE-2026-32953

Medium priority

Not in release

Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the tkeyclient Go module which causes 1 out of every 256 User Supplied Secrets (USS) to be silently ignored,...

1 affected package

golang-github-tillitis-tkeyclient

Package 24.04 LTS
golang-github-tillitis-tkeyclient Not in release
Show less packages

CVE-2026-32829

Medium priority
Needs evaluation

lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from...

1 affected package

rust-lz4-flex

Package 24.04 LTS
rust-lz4-flex Needs evaluation
Show less packages

CVE-2026-4464

Medium priority
Not affected

Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-4463

Medium priority
Not affected

Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages