Search CVE reports


Toggle filters

2771 – 2780 of 35263 results

Status is adjusted based on your filters.


CVE-2026-3731

Medium priority
Fixed

A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing...

1 affected package

libssh

Package 24.04 LTS
libssh Fixed
Show less packages

CVE-2026-3713

Medium priority
Not affected

A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height...

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 24.04 LTS
libpng Not in release
libpng1.6 Not affected
firefox Not affected
thunderbird Not affected
chromium-browser Not affected
Show less packages

CVE-2026-3706

Medium priority
Needs evaluation

A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic...

1 affected package

dropbear

Package 24.04 LTS
dropbear Needs evaluation
Show less packages

CVE-2026-30852

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 double-expands user-controlled input through the Caddy replacer. When vars_regexp...

1 affected package

caddy

Package 24.04 LTS
caddy Needs evaluation
Show less packages

CVE-2026-30851

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation....

1 affected package

caddy

Package 24.04 LTS
caddy Needs evaluation
Show less packages

CVE-2026-30838

Medium priority
Fixed

league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and...

1 affected package

php-league-commonmark

Package 24.04 LTS
php-league-commonmark Fixed
Show less packages

CVE-2026-29786

Medium priority
Needs evaluation

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which...

1 affected package

node-tar

Package 24.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2026-29076

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib uses std::regex (libstdc++) to parse RFC 5987 encoded filename* values in multipart...

1 affected package

cpp-httplib

Package 24.04 LTS
cpp-httplib Needs evaluation
Show less packages

CVE-2026-24308

Medium priority
Needs evaluation

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration...

1 affected package

zookeeper

Package 24.04 LTS
zookeeper Needs evaluation
Show less packages

CVE-2026-24281

Medium priority
Needs evaluation

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid...

1 affected package

zookeeper

Package 24.04 LTS
zookeeper Needs evaluation
Show less packages