Search CVE reports


Toggle filters

121 – 130 of 37431 results

Status is adjusted based on your filters.


CVE-2026-34043

Medium priority
Needs evaluation

Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted...

1 affected package

node-serialize-javascript

Package 22.04 LTS
node-serialize-javascript Needs evaluation
Show less packages

CVE-2026-34040

Medium priority
Needs evaluation

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

2 affected packages

docker.io, docker.io-app

Package 22.04 LTS
docker.io Needs evaluation
docker.io-app Needs evaluation
Show less packages

CVE-2026-34036

Medium priority

Not in release

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX...

1 affected package

dolibarr

Package 22.04 LTS
dolibarr Not in release
Show less packages

CVE-2026-33997

Medium priority
Needs evaluation

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's...

2 affected packages

docker.io, docker.io-app

Package 22.04 LTS
docker.io Needs evaluation
docker.io-app Needs evaluation
Show less packages

CVE-2026-33691

Medium priority
Needs evaluation

[Whitespace padding in filenames bypasses file upload extension checks]

1 affected package

modsecurity-crs

Package 22.04 LTS
modsecurity-crs Needs evaluation
Show less packages

CVE-2026-32884

Medium priority
Needs evaluation

Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict the set of allowable DNS names, if no subject alternative name is defined in the...

3 affected packages

botan, botan1.10, botan3

Package 22.04 LTS
botan Needs evaluation
botan1.10 Not in release
botan3 Not in release
Show less packages

CVE-2026-32883

Medium priority
Needs evaluation

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP...

3 affected packages

botan, botan1.10, botan3

Package 22.04 LTS
botan Needs evaluation
botan1.10 Not in release
botan3 Not in release
Show less packages

CVE-2026-32877

Medium priority
Needs evaluation

Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check that the encoded value was of the expected length...

3 affected packages

botan, botan1.10, botan3

Package 22.04 LTS
botan Needs evaluation
botan1.10 Not in release
botan3 Not in release
Show less packages

CVE-2026-21717

Medium priority
Needs evaluation

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string...

1 affected package

nodejs

Package 22.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-21716

Medium priority
Needs evaluation

An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were...

1 affected package

nodejs

Package 22.04 LTS
nodejs Needs evaluation
Show less packages