Search CVE reports


Toggle filters

11 – 20 of 36937 results

Status is adjusted based on your filters.


CVE-2026-33210

Medium priority
Needs evaluation

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the...

1 affected package

ruby-json

Package 22.04 LTS
ruby-json Needs evaluation
Show less packages

CVE-2026-33186

High priority
Needs evaluation

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in...

2 affected packages

golang-google-grpc, google-guest-agent

Package 22.04 LTS
golang-google-grpc Needs evaluation
google-guest-agent Needs evaluation
Show less packages

CVE-2026-33179

Medium priority
Needs evaluation

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init_queue allows a local user to crash the FUSE daemon or cause...

2 affected packages

fuse, fuse3

Package 22.04 LTS
fuse Needs evaluation
fuse3 Needs evaluation
Show less packages

CVE-2026-33165

Medium priority
Needs evaluation

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize...

1 affected package

libde265

Package 22.04 LTS
libde265 Needs evaluation
Show less packages

CVE-2026-33164

Medium priority
Needs evaluation

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in...

1 affected package

libde265

Package 22.04 LTS
libde265 Needs evaluation
Show less packages

CVE-2026-33155

Medium priority
Needs evaluation

DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _RestrictedUnpickler validates which classes can be loaded but does not limit their...

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 22.04 LTS
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Needs evaluation
python3.11 Needs evaluation
python3.12 Not in release
python3.13 Not in release
python3.14 Not in release
Show all 12 packages Show less packages

CVE-2026-33154

Medium priority
Needs evaluation

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is...

1 affected package

python-dynaconf

Package 22.04 LTS
python-dynaconf Needs evaluation
Show less packages

CVE-2026-33150

Medium priority
Needs evaluation

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem...

2 affected packages

fuse, fuse3

Package 22.04 LTS
fuse Needs evaluation
fuse3 Needs evaluation
Show less packages

CVE-2026-33144

Medium priority
Needs evaluation

GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in...

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-33123

Medium priority

Not in release

pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based...

1 affected package

pypdf

Package 22.04 LTS
pypdf Not in release
Show less packages