Search CVE reports


Toggle filters

81 – 90 of 26733 results

Status is adjusted based on your filters.


CVE-2026-44699

Medium priority
Needs evaluation

LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes...

2 affected packages

libjwt, libjwt3

Package 26.04 LTS
libjwt Needs evaluation
libjwt3 Needs evaluation
Show less packages

CVE-2026-44310

Medium priority
Needs evaluation

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereferences certs[0]...

1 affected package

gitsign

Package 26.04 LTS
gitsign Needs evaluation
Show less packages

CVE-2026-44309

Medium priority
Needs evaluation

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before...

1 affected package

gitsign

Package 26.04 LTS
gitsign Needs evaluation
Show less packages

CVE-2026-34253

Medium priority
Needs evaluation

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing...

1 affected package

vorbis-tools

Package 26.04 LTS
vorbis-tools Needs evaluation
Show less packages

CVE-2026-8503

Medium priority
Needs evaluation

Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator returns a SHA-256 hash of the...

1 affected package

libapache-session-browseable-perl

Package 26.04 LTS
libapache-session-browseable-perl Needs evaluation
Show less packages

CVE-2025-54518

Medium priority
Needs evaluation

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

1 affected package

xen

Package 26.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-6811

Medium priority
Needs evaluation

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

1 affected package

php-mongodb

Package 26.04 LTS
php-mongodb Needs evaluation
Show less packages

CVE-2026-42327

Medium priority
Needs evaluation

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target =...

1 affected package

rust-openssl

Package 26.04 LTS
rust-openssl Needs evaluation
Show less packages

CVE-2026-8585

Medium priority
Not affected

Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium...

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-8581

Medium priority
Not affected

Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages