Search CVE reports


Toggle filters

481 – 490 of 45341 results

Status is adjusted based on your filters.


CVE-2026-38820

Medium priority
Needs evaluation

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

1 affected package

opennds

Package 24.04 LTS
opennds Needs evaluation
Show less packages

CVE-2026-38819

Medium priority
Needs evaluation

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

1 affected package

opennds

Package 24.04 LTS
opennds Needs evaluation
Show less packages

CVE-2026-82072

Medium priority
Not affected

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-80179

Medium priority
Needs evaluation

A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate...

1 affected package

python-jwcrypto

Package 24.04 LTS
python-jwcrypto Needs evaluation
Show less packages

CVE-2026-77358

Medium priority
Needs evaluation

cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In...

1 affected package

cpp-httplib

Package 24.04 LTS
cpp-httplib Needs evaluation
Show less packages

CVE-2026-77341

Medium priority
Needs evaluation

cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a...

1 affected package

cpp-httplib

Package 24.04 LTS
cpp-httplib Needs evaluation
Show less packages

CVE-2026-54330

Medium priority
Needs evaluation

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers...

1 affected package

ceph

Package 24.04 LTS
ceph Needs evaluation
Show less packages

CVE-2026-50152

Medium priority
Needs evaluation

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key...

1 affected package

ceph

Package 24.04 LTS
ceph Needs evaluation
Show less packages

CVE-2026-39944

Medium priority
Needs evaluation

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides...

1 affected package

ceph

Package 24.04 LTS
ceph Needs evaluation
Show less packages

CVE-2026-38350

Medium priority
Needs evaluation

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages