Search CVE reports


Toggle filters

901 – 910 of 45567 results

Status is adjusted based on your filters.


CVE-2026-80205

Medium priority
Needs evaluation

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers...

1 affected package

nltk

Package 24.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-59683

Medium priority

Not in release

The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as...

1 affected package

openrgb

Package 24.04 LTS
openrgb Not in release
Show less packages

CVE-2026-59682

Medium priority

Not in release

Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.

1 affected package

openrgb

Package 24.04 LTS
openrgb Not in release
Show less packages

CVE-2026-18794

Medium priority

Not in release

The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by passing inconsistent data.

1 affected package

openrgb

Package 24.04 LTS
openrgb Not in release
Show less packages

CVE-2026-19538

Medium priority
Needs evaluation

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

1 affected package

nsd

Package 24.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-19401

Medium priority
Needs evaluation

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By...

1 affected package

nsd

Package 24.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-19197

Medium priority

Not in release

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key...

1 affected package

grafana

Package 24.04 LTS
grafana Not in release
Show less packages

CVE-2026-18916

Medium priority
Needs evaluation

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.

1 affected package

nsd

Package 24.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-18664

Medium priority
Needs evaluation

When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were...

1 affected package

nsd

Package 24.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-54467

Medium priority
Needs evaluation

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

1 affected package

arm-trusted-firmware

Package 24.04 LTS
arm-trusted-firmware Needs evaluation
Show less packages