Search CVE reports


Toggle filters

101 – 110 of 33763 results

Status is adjusted based on your filters.


CVE-2026-4660

Medium priority
Needs evaluation

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This...

1 affected package

golang-github-hashicorp-go-getter

Package 24.04 LTS
golang-github-hashicorp-go-getter Needs evaluation
Show less packages

CVE-2026-40046

Medium priority
Needs evaluation

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to...

1 affected package

activemq

Package 24.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-39983

Medium priority
Needs evaluation

basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(),...

1 affected package

node-proxy-agents

Package 24.04 LTS
node-proxy-agents Needs evaluation
Show less packages

CVE-2026-39977

Medium priority
Needs evaluation

flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user defined licence files relative to the source directory of the module. The paths...

1 affected package

flatpak-builder

Package 24.04 LTS
flatpak-builder Needs evaluation
Show less packages

CVE-2026-39856

Medium priority
Needs evaluation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...

1 affected package

osslsigncode

Package 24.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2026-39855

Medium priority
Needs evaluation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...

1 affected package

osslsigncode

Package 24.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2026-39853

Medium priority
Needs evaluation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7...

1 affected package

osslsigncode

Package 24.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2026-39304

Medium priority
Needs evaluation

[Unknown description]

1 affected package

activemq

Package 24.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-35195

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings between components contains a bug where the return value of a guest component's realloc is...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-35186

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backend contains a bug where translating the table.grow operator causes the result to be incorrectly typed. For...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages