Search CVE reports


Toggle filters

201 – 210 of 37431 results

Status is adjusted based on your filters.


CVE-2026-33206

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar...

1 affected package

calibre

Package 22.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-33205

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's...

1 affected package

calibre

Package 22.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-28375

Medium priority

Not in release

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

1 affected package

grafana

Package 22.04 LTS
grafana Not in release
Show less packages

CVE-2026-27880

Medium priority

Not in release

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

1 affected package

grafana

Package 22.04 LTS
grafana Not in release
Show less packages

CVE-2026-27879

Medium priority

Not in release

A resample query can be used to trigger out-of-memory crashes in Grafana.

1 affected package

grafana

Package 22.04 LTS
grafana Not in release
Show less packages

CVE-2026-27877

Medium priority

Not in release

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to...

1 affected package

grafana

Package 22.04 LTS
grafana Not in release
Show less packages

CVE-2026-27876

Medium priority

Not in release

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid...

1 affected package

grafana

Package 22.04 LTS
grafana Not in release
Show less packages

CVE-2026-4948

Medium priority
Needs evaluation

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to...

1 affected package

firewalld

Package 22.04 LTS
firewalld Needs evaluation
Show less packages

CVE-2026-34353

Medium priority
Needs evaluation

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

1 affected package

ocaml

Package 22.04 LTS
ocaml Needs evaluation
Show less packages

CVE-2026-33745

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest Auth credentials to arbitrary hosts when following...

1 affected package

cpp-httplib

Package 22.04 LTS
cpp-httplib Needs evaluation
Show less packages