Search CVE reports


Toggle filters

391 – 400 of 29718 results

Status is adjusted based on your filters.


CVE-2026-39951

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports feature. This issue has been fixed in version 1.2.31.

1 affected package

cacti

Package 26.04 LTS
cacti Needs evaluation
Show less packages

CVE-2025-60473

Medium priority

Not in release

A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

1 affected package

gpac

Package 26.04 LTS
gpac Not in release
Show less packages

CVE-2025-60466

Medium priority

Not in release

A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.

1 affected package

gpac

Package 26.04 LTS
gpac Not in release
Show less packages

CVE-2026-48785

Medium priority
Needs evaluation

[Unknown description]

1 affected package

apptainer

Package 26.04 LTS
apptainer Needs evaluation
Show less packages

CVE-2026-47215

Medium priority
Needs evaluation

[Unknown description]

1 affected package

singularity-container

Package 26.04 LTS
singularity-container Needs evaluation
Show less packages

CVE-2026-12490

Medium priority
Fixed

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular...

1 affected package

nsd

Package 26.04 LTS
nsd Fixed
Show less packages

CVE-2026-12246

Medium priority
Fixed

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111...

1 affected package

nsd

Package 26.04 LTS
nsd Fixed
Show less packages

CVE-2026-12245

Medium priority
Fixed

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the...

1 affected package

nsd

Package 26.04 LTS
nsd Fixed
Show less packages

CVE-2026-12244

Medium priority
Fixed

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used...

1 affected package

nsd

Package 26.04 LTS
nsd Fixed
Show less packages

CVE-2026-39955

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in version 1.2.31.

1 affected package

cacti

Package 26.04 LTS
cacti Needs evaluation
Show less packages