Search CVE reports


Toggle filters

511 – 520 of 42275 results

Status is adjusted based on your filters.


CVE-2026-68580

Medium priority
Needs evaluation

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers....

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Needs evaluation
Show less packages

CVE-2026-68579

Medium priority
Needs evaluation

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Needs evaluation
Show less packages

CVE-2026-9335

Medium priority

Not in release

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the...

1 affected package

keras

Package 24.04 LTS
keras Not in release
Show less packages

CVE-2026-67355

Medium priority
Needs evaluation

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only...

1 affected package

guzzle

Package 24.04 LTS
guzzle Needs evaluation
Show less packages

CVE-2026-67354

Medium priority
Needs evaluation

guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion...

1 affected package

guzzle

Package 24.04 LTS
guzzle Needs evaluation
Show less packages

CVE-2026-67353

Medium priority
Needs evaluation

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a...

1 affected package

guzzle

Package 24.04 LTS
guzzle Needs evaluation
Show less packages

CVE-2026-67339

Medium priority
Needs evaluation

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are...

1 affected package

guzzle

Package 24.04 LTS
guzzle Needs evaluation
Show less packages

CVE-2026-67338

Medium priority

Not in release

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript:...

1 affected package

jupyterlab

Package 24.04 LTS
jupyterlab Not in release
Show less packages

CVE-2026-67326

Medium priority
Needs evaluation

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged...

1 affected package

python-git

Package 24.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-67325

Medium priority
Needs evaluation

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names...

1 affected package

python-git

Package 24.04 LTS
python-git Needs evaluation
Show less packages