Search CVE reports


Toggle filters

681 – 690 of 37431 results

Status is adjusted based on your filters.


CVE-2026-20643

Medium priority
Vulnerable

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 22.04 LTS
webkitgtk Not in release
webkit2gtk Vulnerable
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Ignored
Show less packages

CVE-2026-4359

Medium priority
Needs evaluation

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

1 affected package

mongo-c-driver

Package 22.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-4358

Medium priority

Not in release

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is...

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-32837

Medium priority

Not in release

miniaudio version 0.11.25 and earlier contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted WAV files. Attackers can exploit...

1 affected package

miniaudio

Package 22.04 LTS
miniaudio Not in release
Show less packages

CVE-2026-25936

Medium priority

Not in release

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.

1 affected package

glpi

Package 22.04 LTS
glpi Not in release
Show less packages

CVE-2026-4148

Medium priority

Not in release

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-4147

Medium priority

Not in release

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-3888

High priority
Fixed

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue...

1 affected package

snapd

Package 22.04 LTS
snapd Fixed
Show less packages

CVE-2026-4271

Medium priority
Needs evaluation

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2...

2 affected packages

libsoup2.4, libsoup3

Package 22.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-3634

Medium priority
Vulnerable

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in...

2 affected packages

libsoup2.4, libsoup3

Package 22.04 LTS
libsoup2.4 Vulnerable
libsoup3 Vulnerable
Show less packages