Search CVE reports


Toggle filters

1921 – 1930 of 34564 results

Status is adjusted based on your filters.


CVE-2026-66402

Medium priority
Fixed

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs...

3 affected packages

freerdp, freerdp2, freerdp3

Package 26.04 LTS
freerdp Not in release
freerdp2 Not in release
freerdp3 Fixed
Show less packages

CVE-2026-66401

Medium priority
Fixed

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video...

3 affected packages

freerdp, freerdp2, freerdp3

Package 26.04 LTS
freerdp Not in release
freerdp2 Not in release
freerdp3 Fixed
Show less packages

CVE-2026-18536

Medium priority
Needs evaluation

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The...

1 affected package

libdata-entropy-perl

Package 26.04 LTS
libdata-entropy-perl Needs evaluation
Show less packages

CVE-2026-54909

Medium priority
Needs evaluation

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of...

2 affected packages

golang-github-pion-stun, golang-github-pion-stun-v3

Package 26.04 LTS
golang-github-pion-stun Needs evaluation
golang-github-pion-stun-v3 Needs evaluation
Show less packages

CVE-2026-54787

Medium priority
Needs evaluation

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key...

1 affected package

sigstore-go

Package 26.04 LTS
sigstore-go Needs evaluation
Show less packages

CVE-2026-65981

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against...

1 affected package

coturn

Package 26.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-62959

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and exposes a plaintext-TCP listener, an unauthenticated remote client can send a...

1 affected package

coturn

Package 26.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-53505

Medium priority
Needs evaluation

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger...

1 affected package

thumbor

Package 26.04 LTS
thumbor Needs evaluation
Show less packages

CVE-2026-53504

Medium priority
Needs evaluation

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust...

1 affected package

thumbor

Package 26.04 LTS
thumbor Needs evaluation
Show less packages

CVE-2026-53503

Medium priority
Needs evaluation

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension...

1 affected package

thumbor

Package 26.04 LTS
thumbor Needs evaluation
Show less packages