Search CVE reports


Toggle filters

141 – 150 of 42133 results

Status is adjusted based on your filters.


CVE-2026-12151

Medium priority

Not in release

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-55748

Medium priority
Needs evaluation

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address...

1 affected package

horizon

Package 22.04 LTS
horizon Needs evaluation
Show less packages

CVE-2026-12528

Medium priority
Needs evaluation

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing....

1 affected package

389-ds-base

Package 22.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-49268

Medium priority
Needs evaluation

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of...

1 affected package

shiro

Package 22.04 LTS
shiro Needs evaluation
Show less packages

CVE-2026-48779

Medium priority
Needs evaluation

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a...

1 affected package

node-ws

Package 22.04 LTS
node-ws Needs evaluation
Show less packages

CVE-2026-44587

Medium priority
Needs evaluation

CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in string entries, causing the denylist to silently not...

1 affected package

ruby-carrierwave

Package 22.04 LTS
ruby-carrierwave Needs evaluation
Show less packages

CVE-2026-12199

Medium priority
Needs evaluation

A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The server listens on all interfaces and processes a...

1 affected package

nltk

Package 22.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-46977

Medium priority
Needs evaluation

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon...

1 affected package

virtualbox

Package 22.04 LTS
virtualbox Needs evaluation
Show less packages

CVE-2026-46974

Medium priority
Needs evaluation

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the...

1 affected package

virtualbox

Package 22.04 LTS
virtualbox Needs evaluation
Show less packages

CVE-2026-46877

Medium priority
Needs evaluation

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon...

1 affected package

virtualbox

Package 22.04 LTS
virtualbox Needs evaluation
Show less packages