Search CVE reports


Toggle filters

821 – 830 of 26567 results

Status is adjusted based on your filters.


CVE-2026-28780

Low priority
Fixed

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write...

1 affected package

apache2

Package 26.04 LTS
apache2 Fixed
Show less packages

CVE-2026-24072

Medium priority
Fixed

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which...

1 affected package

apache2

Package 26.04 LTS
apache2 Fixed
Show less packages

CVE-2026-23918

High priority
Fixed

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

1 affected package

apache2

Package 26.04 LTS
apache2 Fixed
Show less packages

CVE-2026-6321

Medium priority
Needs evaluation

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so...

1 affected package

node-ajv

Package 26.04 LTS
node-ajv Needs evaluation
Show less packages

CVE-2026-42154

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body...

1 affected package

prometheus

Package 26.04 LTS
prometheus Needs evaluation
Show less packages

CVE-2026-42151

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string...

1 affected package

prometheus

Package 26.04 LTS
prometheus Needs evaluation
Show less packages

CVE-2026-42146

Medium priority
Needs evaluation

CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A...

1 affected package

cimg

Package 26.04 LTS
cimg Needs evaluation
Show less packages

CVE-2026-42144

Medium priority
Needs evaluation

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted...

1 affected package

cimg

Package 26.04 LTS
cimg Needs evaluation
Show less packages

CVE-2026-42052

Medium priority
Needs evaluation

Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted metadata fields. In this runtime, <%= ... %> is raw insertion and HTML...

1 affected package

beets

Package 26.04 LTS
beets Needs evaluation
Show less packages

CVE-2026-37459

Medium priority
Needs evaluation

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

2 affected packages

frr, quagga

Package 26.04 LTS
frr Needs evaluation
quagga Not in release
Show less packages