Search CVE reports


Toggle filters

271 – 280 of 41462 results

Status is adjusted based on your filters.


CVE-2026-42326

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file a malicious input file could cause an out of bounds read of...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-2049

Medium priority
Needs evaluation

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit...

1 affected package

gegl

Package 20.04 LTS
gegl Needs evaluation
Show less packages

CVE-2026-10143

Medium priority
Needs evaluation

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large...

1 affected package

python-kafka

Package 20.04 LTS
python-kafka Needs evaluation
Show less packages

CVE-2026-10142

Medium priority
Needs evaluation

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame...

1 affected package

python-kafka

Package 20.04 LTS
python-kafka Needs evaluation
Show less packages

CVE-2026-48858

Medium priority
Needs evaluation

Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-11837

Medium priority
Needs evaluation

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing...

2 affected packages

ansible, ansible-core

Package 20.04 LTS
ansible Needs evaluation
ansible-core
Show less packages

CVE-2026-9754

Medium priority
Needs evaluation

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-9753

Medium priority
Needs evaluation

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-9752

Medium priority
Needs evaluation

An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-9751

Medium priority
Needs evaluation

The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages