Search CVE reports


Toggle filters

41 – 50 of 37349 results

Status is adjusted based on your filters.


CVE-2026-25942

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result` indexes the global `error_code_names[]` array (7 elements, indices 0–6) with an...

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-25941

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel...

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2025-11563

Medium priority
Not affected

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

1 affected package

curl

Package 20.04 LTS
curl Not affected
Show less packages

CVE-2026-27624

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed...

1 affected package

coturn

Package 20.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-3147

Medium priority
Needs evaluation

A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local...

1 affected package

vips

Package 20.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3146

Medium priority
Needs evaluation

A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack...

1 affected package

vips

Package 20.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-3145

Medium priority
Needs evaluation

A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. Executing a manipulation can lead to...

1 affected package

vips

Package 20.04 LTS
vips Needs evaluation
Show less packages

CVE-2026-27628

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2....

2 affected packages

pypdf, pypdf2

Package 20.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-27606

Medium priority
Needs evaluation

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal....

1 affected package

node-rollup

Package 20.04 LTS
node-rollup Needs evaluation
Show less packages

CVE-2026-3099

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

libsoup2.4, libsoup3

Package 20.04 LTS
libsoup2.4 Needs evaluation
libsoup3
Show less packages