Search CVE reports


Toggle filters

2211 – 2220 of 45973 results

Status is adjusted based on your filters.


CVE-2026-63336

Medium priority
Needs evaluation

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol()...

1 affected package

rabbitmq-java-client

Package 24.04 LTS
rabbitmq-java-client Needs evaluation
Show less packages

CVE-2026-63335

Medium priority
Needs evaluation

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java...

1 affected package

rabbitmq-java-client

Package 24.04 LTS
rabbitmq-java-client Needs evaluation
Show less packages

CVE-2026-61634

Medium priority
Needs evaluation

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value,...

1 affected package

rabbitmq-java-client

Package 24.04 LTS
rabbitmq-java-client Needs evaluation
Show less packages

CVE-2026-75926

Medium priority
Needs evaluation

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0...

1 affected package

hugo

Package 24.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-75904

Medium priority
Needs evaluation

libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte...

2 affected packages

libmodplug, gst-plugins-bad0.10

Package 24.04 LTS
libmodplug Needs evaluation
gst-plugins-bad0.10 Not in release
Show less packages

CVE-2026-15806

Medium priority
Needs evaluation

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 24.04 LTS
python2.7 Not in release
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Not in release
python3.11 Not in release
python3.12 Needs evaluation
python3.14 Not in release
Show all 11 packages Show less packages

CVE-2026-75032

Medium priority
Needs evaluation

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause...

1 affected package

bluez

Package 24.04 LTS
bluez Needs evaluation
Show less packages

CVE-2026-68939

Medium priority

Not in release

Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in...

1 affected package

pyenv

Package 24.04 LTS
pyenv Not in release
Show less packages

CVE-2026-66046

Medium priority
Vulnerable

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an...

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS
expat Vulnerable
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-63639

Medium priority
Needs evaluation

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during...

1 affected package

valkey

Package 24.04 LTS
valkey Needs evaluation
Show less packages