Search CVE reports


Toggle filters

141 – 150 of 33695 results

Status is adjusted based on your filters.


CVE-2026-39892

Medium priority
Not affected

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g....

1 affected package

python-cryptography

Package 24.04 LTS
python-cryptography Not affected
Show less packages

CVE-2026-39883

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the...

1 affected package

golang-opentelemetry-otel

Package 24.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages

CVE-2026-39882

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for...

1 affected package

golang-opentelemetry-otel

Package 24.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages

CVE-2026-39865

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-39864

Medium priority
Needs evaluation

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service...

1 affected package

kamailio

Package 24.04 LTS
kamailio Needs evaluation
Show less packages

CVE-2026-39863

Medium priority
Needs evaluation

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service...

1 affected package

kamailio

Package 24.04 LTS
kamailio Needs evaluation
Show less packages

CVE-2026-34757

Medium priority
Needs evaluation

[Use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` leading to corrupted chunk data and potential heap information disclosure]

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 24.04 LTS
libpng Not in release
libpng1.6 Needs evaluation
firefox Not affected
thunderbird Not affected
chromium-browser Not affected
Show less packages

CVE-2026-2619

Medium priority

Not in release

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2026-2104

Medium priority

Not in release

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages

CVE-2026-1752

Medium priority

Not in release

GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify...

1 affected package

gitlab

Package 24.04 LTS
gitlab Not in release
Show less packages