Search CVE reports


Toggle filters

101 – 110 of 28995 results

Status is adjusted based on your filters.


CVE-2026-45696

Medium priority
Needs evaluation

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl() in...

1 affected package

openexr

Package 26.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-44663

Medium priority
Needs evaluation

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, an integer overflow in ht_undo_impl()...

1 affected package

openexr

Package 26.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-43994

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). A uint16_t nonce_len field read from an attacker-supplied OAuth access...

1 affected package

coturn

Package 26.04 LTS
coturn Needs evaluation
Show less packages

CVE-2025-15661

Medium priority
Needs evaluation

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap...

1 affected package

libssh2

Package 26.04 LTS
libssh2 Needs evaluation
Show less packages

CVE-2026-43915

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation...

1 affected package

coturn

Package 26.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-55392

Medium priority
Needs evaluation

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger...

1 affected package

nilfs-tools

Package 26.04 LTS
nilfs-tools Needs evaluation
Show less packages

CVE-2026-48937

Medium priority
Needs evaluation

A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.

1 affected package

nodejs

Package 26.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-48617

Medium priority
Needs evaluation

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations....

1 affected package

nodejs

Package 26.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-46580

Medium priority

Not in release

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a...

1 affected package

eclipse

Package 26.04 LTS
eclipse Not in release
Show less packages

CVE-2026-44691

Medium priority

Not in release

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository...

1 affected package

eclipse

Package 26.04 LTS
eclipse Not in release
Show less packages