Search CVE reports


Toggle filters

231 – 240 of 37641 results

Status is adjusted based on your filters.


CVE-2026-34876

Medium priority
Needs evaluation

An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with...

1 affected package

mbedtls

Package 22.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-33691

Medium priority
Needs evaluation

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with...

1 affected package

modsecurity-crs

Package 22.04 LTS
modsecurity-crs Needs evaluation
Show less packages

CVE-2026-5342

Medium priority
Needs evaluation

A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw.cpp of the component TIFF/NEF. Executing a manipulation of the argument...

8 affected packages

libraw, ufraw, darktable, exactimage, dcraw...

Package 22.04 LTS
libraw Needs evaluation
ufraw Not in release
darktable Needs evaluation
exactimage Needs evaluation
dcraw Needs evaluation
rawtherapee Needs evaluation
kodi Needs evaluation
digikam Needs evaluation
Show all 8 packages Show less packages

CVE-2026-33641

Medium priority
Needs evaluation

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration...

1 affected package

glances

Package 22.04 LTS
glances Needs evaluation
Show less packages

CVE-2026-33533

Medium priority
Needs evaluation

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response....

1 affected package

glances

Package 22.04 LTS
glances Needs evaluation
Show less packages

CVE-2026-31937

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in version 7.0.15.

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-31935

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the...

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-31934

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This...

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-31933

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in versions 7.0.15 and 8.0.4.

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages

CVE-2026-31932

Medium priority
Needs evaluation

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.

1 affected package

suricata

Package 22.04 LTS
suricata Needs evaluation
Show less packages