Search CVE reports


Toggle filters

21 – 30 of 33266 results

Status is adjusted based on your filters.


CVE-2026-33762

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS
golang-github-go-git-go-git Needs evaluation
Show less packages

CVE-2026-33276

Medium priority

Not in release

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in...

1 affected package

check-mk

Package 24.04 LTS
check-mk Not in release
Show less packages

CVE-2026-3308

Medium priority
Needs evaluation

An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap...

1 affected package

mupdf

Package 24.04 LTS
mupdf Needs evaluation
Show less packages

CVE-2026-32726

Medium priority
Needs evaluation

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple...

1 affected package

scitokens-cpp

Package 24.04 LTS
scitokens-cpp Needs evaluation
Show less packages

CVE-2026-32725

Medium priority
Needs evaluation

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes...

1 affected package

scitokens-cpp

Package 24.04 LTS
scitokens-cpp Needs evaluation
Show less packages

CVE-2026-2950

Medium priority
Needs evaluation

Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only...

1 affected package

node-lodash

Package 24.04 LTS
node-lodash Needs evaluation
Show less packages

CVE-2026-27489

Medium priority
Needs evaluation

(Open Neural Network Exchange (ONNX) is an open standard for machine le ...)

1 affected package

onnx

Package 24.04 LTS
onnx Needs evaluation
Show less packages

CVE-2026-25835

Medium priority
Needs evaluation

(Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a ...)

1 affected package

mbedtls

Package 24.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-25834

Medium priority
Needs evaluation

(Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.)

1 affected package

mbedtls

Package 24.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-25833

Medium priority
Needs evaluation

(Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow ...)

1 affected package

mbedtls

Package 24.04 LTS
mbedtls Needs evaluation
Show less packages