Search CVE reports


Toggle filters

2391 – 2400 of 35647 results

Status is adjusted based on your filters.


CVE-2026-34441

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses...

1 affected package

cpp-httplib

Package 24.04 LTS
cpp-httplib Needs evaluation
Show less packages

CVE-2026-4800

Medium priority
Needs evaluation

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into...

1 affected package

node-lodash

Package 24.04 LTS
node-lodash Needs evaluation
Show less packages

CVE-2026-2950

Medium priority
Needs evaluation

Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only...

1 affected package

node-lodash

Package 24.04 LTS
node-lodash Needs evaluation
Show less packages

CVE-2026-32726

Medium priority
Needs evaluation

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple...

1 affected package

scitokens-cpp

Package 24.04 LTS
scitokens-cpp Needs evaluation
Show less packages

CVE-2026-32725

Medium priority
Needs evaluation

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes...

1 affected package

scitokens-cpp

Package 24.04 LTS
scitokens-cpp Needs evaluation
Show less packages

CVE-2026-34235

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted VP9 Scalability...

1 affected package

pjproject

Package 24.04 LTS
pjproject Not in release
Show less packages

CVE-2026-34165

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS
golang-github-go-git-go-git Needs evaluation
Show less packages

CVE-2026-33762

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS
golang-github-go-git-go-git Needs evaluation
Show less packages

CVE-2026-33276

Medium priority

Not in release

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in...

1 affected package

check-mk

Package 24.04 LTS
check-mk Not in release
Show less packages

CVE-2026-20915

Medium priority

Not in release

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will...

1 affected package

check-mk

Package 24.04 LTS
check-mk Not in release
Show less packages