Search CVE reports


Toggle filters

841 – 850 of 37324 results

Status is adjusted based on your filters.


CVE-2026-27141

Medium priority
Not affected

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 22.04 LTS
golang-golang-x-net Not affected
google-guest-agent Not affected
containerd Not affected
golang-golang-x-net-dev Not in release
adsys Not affected
juju-core Not in release
lxd Not in release
Show all 7 packages Show less packages

CVE-2026-28296

Medium priority
Fixed

A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized...

1 affected package

gvfs

Package 22.04 LTS
gvfs Fixed
Show less packages

CVE-2026-28295

Medium priority
Fixed

A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information...

1 affected package

gvfs

Package 22.04 LTS
gvfs Fixed
Show less packages

CVE-2025-64999

Medium priority

Not in release

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into the Synthetic Monitoring HTML...

1 affected package

check-mk

Package 22.04 LTS
check-mk Not in release
Show less packages

CVE-2026-27970

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability...

1 affected package

angular.js

Package 22.04 LTS
angular.js Needs evaluation
Show less packages

CVE-2026-27942

Medium priority

Not in release

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML...

1 affected package

node-webfont

Package 22.04 LTS
node-webfont Not in release
Show less packages

CVE-2026-3184

Medium priority
Not affected

[Access control bypass due to improper hostname canonicalization]

1 affected package

util-linux

Package 22.04 LTS
util-linux Not affected
Show less packages

CVE-2026-27904

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with...

1 affected package

node-minimatch

Package 22.04 LTS
node-minimatch Needs evaluation
Show less packages

CVE-2026-27903

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive...

1 affected package

node-minimatch

Package 22.04 LTS
node-minimatch Needs evaluation
Show less packages

CVE-2026-27888

Medium priority

Not in release

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader...

1 affected package

pypdf

Package 22.04 LTS
pypdf Not in release
Show less packages