Search CVE reports


Toggle filters

131 – 140 of 39027 results

Status is adjusted based on your filters.


CVE-2026-62364

Medium priority
Needs evaluation

wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied...

1 affected package

wlc

Package 26.04 LTS
wlc Needs evaluation
Show less packages

CVE-2026-88350

Medium priority
Needs evaluation

An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().

1 affected package

mpack

Package 26.04 LTS
mpack Needs evaluation
Show less packages

CVE-2026-88341

Medium priority
Needs evaluation

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion...

1 affected package

yara

Package 26.04 LTS
yara Needs evaluation
Show less packages

CVE-2026-88340

Medium priority
Needs evaluation

An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free...

1 affected package

yara

Package 26.04 LTS
yara Needs evaluation
Show less packages

CVE-2026-88339

Medium priority

Not in release

A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can...

1 affected package

gpac

Package 26.04 LTS
gpac Not in release
Show less packages

CVE-2026-87121

Medium priority
Needs evaluation

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

1 affected package

lwip

Package 26.04 LTS
lwip Needs evaluation
Show less packages

CVE-2026-75432

Medium priority
Needs evaluation

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

1 affected package

yaml-cpp

Package 26.04 LTS
yaml-cpp Needs evaluation
Show less packages

CVE-2026-59991

Medium priority
Needs evaluation

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height,...

1 affected package

psd-tools

Package 26.04 LTS
psd-tools Needs evaluation
Show less packages

CVE-2026-77399

Medium priority
Needs evaluation

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can...

1 affected package

python-icalendar

Package 26.04 LTS
python-icalendar Needs evaluation
Show less packages

CVE-2026-83597

Medium priority

Not in release

Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A...

1 affected package

netdata

Package 26.04 LTS
netdata Not in release
Show less packages