Search CVE reports


Toggle filters

1761 – 1770 of 45973 results

Status is adjusted based on your filters.


CVE-2026-10618

Medium priority
Needs evaluation

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value...

1 affected package

hugo

Package 24.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-10582

Medium priority
Needs evaluation

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern...

1 affected package

hugo

Package 24.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-75975

Medium priority
Needs evaluation

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a...

1 affected package

node-ajv

Package 24.04 LTS
node-ajv Needs evaluation
Show less packages

CVE-2026-75931

Medium priority
Needs evaluation

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its...

1 affected package

node-ajv

Package 24.04 LTS
node-ajv Needs evaluation
Show less packages

CVE-2026-75899

Medium priority
Needs evaluation

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn...

1 affected package

node-ajv

Package 24.04 LTS
node-ajv Needs evaluation
Show less packages

CVE-2026-66897

Medium priority

Not in release

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When...

1 affected package

lxd

Package 24.04 LTS
lxd Not in release
Show less packages

CVE-2026-78161

Medium priority
Needs evaluation

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can...

1 affected package

libwebsockets

Package 24.04 LTS
libwebsockets Needs evaluation
Show less packages

CVE-2026-78148

Medium priority

Not in release

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation can lead to...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-78147

Medium priority

Not in release

A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-78183

Medium priority
Needs evaluation

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf,...

1 affected package

libdbd-pg-perl

Package 24.04 LTS
libdbd-pg-perl Needs evaluation
Show less packages