Search CVE reports


Toggle filters

311 – 320 of 45341 results

Status is adjusted based on your filters.


CVE-2026-82591

Medium priority
Needs evaluation

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the...

1 affected package

assimp

Package 24.04 LTS
assimp Needs evaluation
Show less packages

CVE-2026-82562

Medium priority
Needs evaluation

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while...

1 affected package

node-qs

Package 24.04 LTS
node-qs Needs evaluation
Show less packages

CVE-2026-82417

Medium priority
Needs evaluation

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by...

1 affected package

node-qs

Package 24.04 LTS
node-qs Needs evaluation
Show less packages

CVE-2026-82474

Medium priority
Needs evaluation

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through...

1 affected package

sudo

Package 24.04 LTS
sudo Needs evaluation
Show less packages

CVE-2026-82470

Medium priority

Not in release

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82469

Medium priority

Not in release

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82468

Medium priority

Not in release

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82467

Medium priority

Not in release

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82466

Medium priority

Not in release

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82481

Medium priority
Needs evaluation

The cohttp package before 6.3.0 for OCaml allows directory traversal.

1 affected package

ocaml-cohttp

Package 24.04 LTS
ocaml-cohttp Needs evaluation
Show less packages