Search CVE reports


Toggle filters

211 – 220 of 37368 results

Status is adjusted based on your filters.


CVE-2026-33219

Medium priority

Not in release

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in...

1 affected package

nats-server

Package 22.04 LTS
nats-server Not in release
Show less packages

CVE-2026-33218

Medium priority

Not in release

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain...

1 affected package

nats-server

Package 22.04 LTS
nats-server Not in release
Show less packages

CVE-2026-33217

Medium priority

Not in release

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace,...

1 affected package

nats-server

Package 22.04 LTS
nats-server Not in release
Show less packages

CVE-2026-33216

Medium priority

Not in release

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a...

1 affected package

nats-server

Package 22.04 LTS
nats-server Not in release
Show less packages

CVE-2026-29785

Medium priority

Not in release

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can...

1 affected package

nats-server

Package 22.04 LTS
nats-server Not in release
Show less packages

CVE-2026-27889

Medium priority

Not in release

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a...

1 affected package

nats-server

Package 22.04 LTS
nats-server Not in release
Show less packages

CVE-2025-70888

Medium priority
Needs evaluation

An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component

1 affected package

osslsigncode

Package 22.04 LTS
osslsigncode Needs evaluation
Show less packages

CVE-2025-70952

Medium priority
Needs evaluation

pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper...

2 affected packages

libpf4j-java, libpf4j-update-java

Package 22.04 LTS
libpf4j-java Needs evaluation
libpf4j-update-java Needs evaluation
Show less packages

CVE-2025-67030

Medium priority

Not in release

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

1 affected package

plexus-utils

Package 22.04 LTS
plexus-utils Not in release
Show less packages

CVE-2026-34085

Medium priority
Not affected

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

1 affected package

fontconfig

Package 22.04 LTS
fontconfig Not affected
Show less packages