Search CVE reports


Toggle filters

121 – 130 of 50227 results

Status is adjusted based on your filters.


CVE-2026-48188

Medium priority
Needs evaluation

(An improper Input Validation vulnerability in OTRS or ((OTRS)) Communi ...)

2 affected packages

znuny, otrs2

Package 20.04 LTS
znuny —
otrs2 Needs evaluation
Show less packages

CVE-2026-46675

Medium priority
Needs evaluation

[Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression]

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 20.04 LTS
libpng —
libpng1.6 Needs evaluation
firefox —
thunderbird —
chromium-browser —
Show less packages

CVE-2026-35191

Low priority
Not affected

QUIC Unvalidated Amplification Credit may be Over Accounted

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 20.04 LTS
openssl Not affected
openssl-fips —
openssl1.0 —
nodejs Not affected
edk2 Not affected
edk2-hwe —
Show less packages

CVE-2026-35189

Low priority
Needs evaluation

Excessive Memory Allocation in Relative CRLDP Processing

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 20.04 LTS
openssl Needs evaluation
openssl-fips —
openssl1.0 —
nodejs Not affected
edk2 Needs evaluation
edk2-hwe —
Show less packages

CVE-2026-15442

Medium priority
Needs evaluation

In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a...

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-102414

Medium priority
Needs evaluation

pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is...

1 affected package

node-pbkdf2

Package 20.04 LTS
node-pbkdf2 Needs evaluation
Show less packages

CVE-2026-102297

Medium priority
Needs evaluation

ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are...

1 affected package

zoneminder

Package 20.04 LTS
zoneminder Needs evaluation
Show less packages

CVE-2026-102296

Medium priority
Needs evaluation

ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response...

1 affected package

zoneminder

Package 20.04 LTS
zoneminder Needs evaluation
Show less packages

CVE-2026-102278

Medium priority
Needs evaluation

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member...

1 affected package

node-brace-expansion

Package 20.04 LTS
node-brace-expansion Needs evaluation
Show less packages

CVE-2026-102277

Medium priority
Needs evaluation

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing...

1 affected package

node-brace-expansion

Package 20.04 LTS
node-brace-expansion Needs evaluation
Show less packages