Search CVE reports


Toggle filters

121 – 130 of 32108 results

Status is adjusted based on your filters.


CVE-2026-26014

Medium priority
Needs evaluation

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.1.0 use random nonce generation with AES GCM ciphers, which makes it easier for remote attackers to obtain...

2 affected packages

golang-github-pion-dtls-v3, golang-github-pion-dtls.v2

Package 24.04 LTS
golang-github-pion-dtls-v3 Not in release
golang-github-pion-dtls.v2 Needs evaluation
Show less packages

CVE-2026-26007

Medium priority
Needs evaluation

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or...

1 affected package

python-cryptography

Package 24.04 LTS
python-cryptography Needs evaluation
Show less packages

CVE-2026-25994

High priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

1 affected package

pjproject

Package 24.04 LTS
pjproject Not in release
Show less packages

CVE-2026-25990

Medium priority
Not affected

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

2 affected packages

pillow, pillow-python2

Package 24.04 LTS
pillow Not affected
pillow-python2 Not in release
Show less packages

CVE-2026-25924

Medium priority
Needs evaluation

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution...

2 affected packages

kanboard-cli, python-kanboard

Package 24.04 LTS
kanboard-cli Needs evaluation
python-kanboard Needs evaluation
Show less packages

CVE-2026-2391

Medium priority
Needs evaluation

### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit...

1 affected package

node-qs

Package 24.04 LTS
node-qs Needs evaluation
Show less packages

CVE-2026-2369

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-2327

Medium priority
Needs evaluation

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of...

1 affected package

node-markdown-it

Package 24.04 LTS
node-markdown-it Needs evaluation
Show less packages

CVE-2026-2323

Medium priority
Not affected

Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-2322

Medium priority
Not affected

Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security...

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages