Search CVE reports


Toggle filters

181 – 190 of 42038 results

Status is adjusted based on your filters.


CVE-2026-68743

Medium priority
Needs evaluation

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted...

1 affected package

sssd

Package 24.04 LTS
sssd Needs evaluation
Show less packages

CVE-2026-47781

Medium priority

Not in release

PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an...

1 affected package

pdm

Package 24.04 LTS
pdm Not in release
Show less packages

CVE-2026-47764

Medium priority

Not in release

pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs()...

1 affected package

pdm

Package 24.04 LTS
pdm Not in release
Show less packages

CVE-2026-47763

Medium priority

Not in release

pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository...

1 affected package

pdm

Package 24.04 LTS
pdm Not in release
Show less packages

CVE-2026-56848

Medium priority
Needs evaluation

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**,...

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-18785

Medium priority

Not in release

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a...

1 affected package

open62541

Package 24.04 LTS
open62541 Not in release
Show less packages

CVE-2026-18784

Medium priority

Not in release

A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow....

1 affected package

open62541

Package 24.04 LTS
open62541 Not in release
Show less packages

CVE-2026-15920

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with...

1 affected package

python-django

Package 24.04 LTS
python-django Needs evaluation
Show less packages

CVE-2026-15830

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects...

1 affected package

python-django

Package 24.04 LTS
python-django Needs evaluation
Show less packages

CVE-2026-15337

Medium priority
Needs evaluation

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which...

1 affected package

python-django

Package 24.04 LTS
python-django Needs evaluation
Show less packages