Search CVE reports


Toggle filters

2321 – 2330 of 37984 results

Status is adjusted based on your filters.


CVE-2026-1484

Medium priority
Fixed

A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory...

1 affected package

glib2.0

Package 22.04 LTS
glib2.0 Fixed
Show less packages

CVE-2026-1467

Medium priority

Some fixes available 1 of 2

A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to...

2 affected packages

libsoup3, libsoup2.4

Package 22.04 LTS
libsoup3 Fixed
libsoup2.4 Vulnerable
Show less packages

CVE-2026-24808

Medium priority
Needs evaluation

Integer Overflow or Wraparound vulnerability in RawTherapee (rtengine modules). This vulnerability is associated with program files dcraw.Cc. This issue affects RawTherapee: through 5.11.

1 affected package

rawtherapee

Package 22.04 LTS
rawtherapee Needs evaluation
Show less packages

CVE-2026-21721

Medium priority

Not in release

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and...

1 affected package

grafana

Package 22.04 LTS
grafana Not in release
Show less packages

CVE-2026-21720

Medium priority

Not in release

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result,...

1 affected package

grafana

Package 22.04 LTS
grafana Not in release
Show less packages

CVE-2026-24686

Medium priority

Not in release

go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory....

1 affected package

golang-github-theupdateframework-go-tuf

Package 22.04 LTS
golang-github-theupdateframework-go-tuf Not in release
Show less packages

CVE-2026-24486

Medium priority
Fixed

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can...

1 affected package

python-multipart

Package 22.04 LTS
python-multipart Fixed
Show less packages

CVE-2026-24480

Medium priority
Needs evaluation

QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actions workflow called "pre-commit checks" that, before commit 76a693cd91650f9b4e83edac525e5e4f90d954e9,...

1 affected package

qgis

Package 22.04 LTS
qgis Needs evaluation
Show less packages

CVE-2026-22796

Low priority

Some fixes available 1 of 3

Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 22.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Vulnerable
edk2 Needs evaluation
Show less packages

CVE-2026-22795

Low priority

Some fixes available 1 of 2

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or...

4 affected packages

openssl, openssl1.0, nodejs, edk2

Package 22.04 LTS
openssl Fixed
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
Show less packages