Search CVE reports


Toggle filters

61 – 70 of 32405 results

Status is adjusted based on your filters.


CVE-2026-3146

Medium priority
Needs evaluation

A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack...

1 affected package

vips

Package 24.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3145

Medium priority
Needs evaluation

A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. Executing a manipulation can lead to...

1 affected package

vips

Package 24.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-27628

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2....

2 affected packages

pypdf, pypdf2

Package 24.04 LTS
pypdf Needs evaluation
pypdf2 Needs evaluation
Show less packages

CVE-2026-27606

Medium priority
Needs evaluation

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal....

1 affected package

node-rollup

Package 24.04 LTS
node-rollup Needs evaluation
Show less packages

CVE-2026-3099

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-27572

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-27204

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-27195

Medium priority
Not affected

Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the default, which brought with it a new implementation of `[Typed]Func::call_async` which made it capable of calling...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Not affected
Show less packages

CVE-2026-27590

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and then uses that byte index to...

1 affected package

caddy

Package 24.04 LTS
caddy Needs evaluation
Show less packages

CVE-2026-27589

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint that replaces the entire running...

1 affected package

caddy

Package 24.04 LTS
caddy Needs evaluation
Show less packages