Search CVE reports


Toggle filters

661 – 670 of 39983 results

Status is adjusted based on your filters.


CVE-2026-29168

Low priority
Needs evaluation

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to...

1 affected package

apache2

Package 20.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-28780

Low priority
Needs evaluation

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write...

1 affected package

apache2

Package 20.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-24072

Medium priority
Needs evaluation

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which...

1 affected package

apache2

Package 20.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-23918

High priority
Not affected

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

1 affected package

apache2

Package 20.04 LTS
apache2 Not affected
Show less packages

CVE-2026-6321

Medium priority
Needs evaluation

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so...

1 affected package

node-ajv

Package 20.04 LTS
node-ajv Needs evaluation
Show less packages

CVE-2026-42154

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body...

1 affected package

prometheus

Package 20.04 LTS
prometheus Needs evaluation
Show less packages

CVE-2026-42151

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string...

1 affected package

prometheus

Package 20.04 LTS
prometheus Needs evaluation
Show less packages

CVE-2026-42146

Medium priority
Needs evaluation

CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A...

1 affected package

cimg

Package 20.04 LTS
cimg Needs evaluation
Show less packages

CVE-2026-42144

Medium priority
Needs evaluation

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted...

1 affected package

cimg

Package 20.04 LTS
cimg Needs evaluation
Show less packages

CVE-2026-42052

Medium priority
Needs evaluation

Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted metadata fields. In this runtime, <%= ... %> is raw insertion and HTML...

1 affected package

beets

Package 20.04 LTS
beets Needs evaluation
Show less packages