Search CVE reports


Toggle filters

191 – 200 of 26733 results

Status is adjusted based on your filters.


CVE-2026-42926

Medium priority
Needs evaluation

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer.  Note: Software...

1 affected package

nginx

Package 26.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-42557

Medium priority
Needs evaluation

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command...

1 affected package

jupyterlab

Package 26.04 LTS
jupyterlab Needs evaluation
Show less packages

CVE-2026-42266

Medium priority
Needs evaluation

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager...

1 affected package

jupyterlab

Package 26.04 LTS
jupyterlab Needs evaluation
Show less packages

CVE-2026-40701

Medium priority
Needs evaluation

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are...

1 affected package

nginx

Package 26.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-40460

Medium priority
Needs evaluation

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions...

1 affected package

nginx

Package 26.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-41051

Medium priority
Needs evaluation

csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.

1 affected package

csync2

Package 26.04 LTS
csync2 Needs evaluation
Show less packages

CVE-2026-8200

Medium priority

Not in release

When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted. This issue impacts MongoDB Server v7.0...

1 affected package

mongodb

Package 26.04 LTS
mongodb Not in release
Show less packages

CVE-2026-8199

Medium priority

Not in release

An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss...

1 affected package

mongodb

Package 26.04 LTS
mongodb Not in release
Show less packages

CVE-2026-8430

Medium priority
Needs evaluation

(SPIP versions prior to 4.4.14 contain a remote code execution vulnerab ...)

1 affected package

spip

Package 26.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-8401

Medium priority
Not affected

(Sandbox escape in the Profile Backup component. This vulnerability was ...)

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Not in release
mozjs115 Not in release
Show all 9 packages Show less packages