Search CVE reports


Toggle filters

1741 – 1750 of 45973 results

Status is adjusted based on your filters.


CVE-2026-53532

Medium priority
Needs evaluation

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process...

1 affected package

openexr

Package 24.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-77337

Medium priority

Not in release

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and...

1 affected package

cakephp

Package 24.04 LTS
cakephp Not in release
Show less packages

CVE-2026-68516

Medium priority
Needs evaluation

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal...

1 affected package

openexr

Package 24.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-45404

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not...

1 affected package

golang-opentelemetry-otel

Package 24.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages

CVE-2026-17113

Medium priority

Not in release

A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request...

1 affected package

cri-o

Package 24.04 LTS
cri-o Not in release
Show less packages

CVE-2026-77635

Medium priority

Not in release

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled...

1 affected package

cakephp

Package 24.04 LTS
cakephp Not in release
Show less packages

CVE-2026-77634

Medium priority

Not in release

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not...

1 affected package

cakephp

Package 24.04 LTS
cakephp Not in release
Show less packages

CVE-2026-77310

Medium priority
Needs evaluation

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines,...

1 affected package

jackson-databind

Package 24.04 LTS
jackson-databind Needs evaluation
Show less packages

CVE-2026-76816

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names...

1 affected package

netty

Package 24.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-76098

Medium priority
Needs evaluation

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk...

1 affected package

mistune

Package 24.04 LTS
mistune Needs evaluation
Show less packages