Search CVE reports


Toggle filters

371 – 380 of 32959 results

Status is adjusted based on your filters.


CVE-2026-13379

Medium priority
Needs evaluation

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

1 affected package

openvpn

Package 26.04 LTS
openvpn Needs evaluation
Show less packages

CVE-2026-60075

Medium priority
Needs evaluation

Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution...

1 affected package

libdate-manip-perl

Package 26.04 LTS
libdate-manip-perl Needs evaluation
Show less packages

CVE-2026-60074

Medium priority
Needs evaluation

Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character...

1 affected package

libdate-manip-perl

Package 26.04 LTS
libdate-manip-perl Needs evaluation
Show less packages

CVE-2026-7260

Medium priority
Needs evaluation

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 26.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Not in release
php7.4 Not in release
php8.1 Not in release
php8.3 Not in release
php8.5 Needs evaluation
Show all 7 packages Show less packages

CVE-2026-17544

Medium priority
Needs evaluation

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 26.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Not in release
php7.4 Not in release
php8.1 Not in release
php8.3 Not in release
php8.5 Needs evaluation
Show all 7 packages Show less packages

CVE-2026-17543

Medium priority
Needs evaluation

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 26.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Not in release
php7.4 Not in release
php8.1 Not in release
php8.3 Not in release
php8.5 Needs evaluation
Show all 7 packages Show less packages

CVE-2026-18369

Medium priority

Not in release

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address....

1 affected package

dogtag-pki

Package 26.04 LTS
dogtag-pki Not in release
Show less packages

CVE-2026-58043

Medium priority
Needs evaluation

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or...

1 affected package

nodejs

Package 26.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-58040

Medium priority
Needs evaluation

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

1 affected package

nodejs

Package 26.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-56850

Medium priority
Needs evaluation

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability...

1 affected package

nodejs

Package 26.04 LTS
nodejs Needs evaluation
Show less packages