Search CVE reports


Toggle filters

141 – 150 of 49076 results

Status is adjusted based on your filters.


CVE-2026-47679

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-46675

Medium priority
Needs evaluation

[Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression]

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 24.04 LTS
libpng Not in release
libpng1.6 Needs evaluation
firefox Not affected
thunderbird Not affected
chromium-browser Not affected
Show less packages

CVE-2026-45801

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-35191

Low priority
Not affected

QUIC Unvalidated Amplification Credit may be Over Accounted

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 24.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-35189

Low priority

Some fixes available 1 of 2

Excessive Memory Allocation in Relative CRLDP Processing

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 24.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
edk2-hwe Not in release
Show less packages

CVE-2026-15442

Medium priority
Needs evaluation

In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a...

1 affected package

wolfssl

Package 24.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-102422

Medium priority
Needs evaluation

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028,...

1 affected package

node-shell-quote

Package 24.04 LTS
node-shell-quote Needs evaluation
Show less packages

CVE-2026-102414

Medium priority
Needs evaluation

pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is...

1 affected package

node-pbkdf2

Package 24.04 LTS
node-pbkdf2 Needs evaluation
Show less packages

CVE-2026-102371

Medium priority
Vulnerable

In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument...

1 affected package

wsl-pro-service

Package 24.04 LTS
wsl-pro-service Vulnerable
Show less packages

CVE-2026-102297

Medium priority
Needs evaluation

ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are...

1 affected package

zoneminder

Package 24.04 LTS
zoneminder Needs evaluation
Show less packages