Search CVE reports


Toggle filters

1721 – 1730 of 47890 results

Status is adjusted based on your filters.


CVE-2026-13505

Medium priority
Needs evaluation

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and...

1 affected package

bouncycastle

Package 22.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-8798

Medium priority
Needs evaluation

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSEED and RDRAND report failure through their carry flag, and...

1 affected package

bouncycastle

Package 22.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-48122

Medium priority

Not in release

Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version 0.10.4 could override the path to the Ruby executable, the version manager...

1 affected package

ruby-ruby-lsp

Package 22.04 LTS
ruby-ruby-lsp Not in release
Show less packages

CVE-2026-48120

Medium priority
Needs evaluation

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply...

1 affected package

kakoune

Package 22.04 LTS
kakoune Needs evaluation
Show less packages

CVE-2026-54338

Medium priority
Needs evaluation

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login...

1 affected package

jupyterhub

Package 22.04 LTS
jupyterhub Needs evaluation
Show less packages

CVE-2026-71870

Medium priority

Not in release

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens...

1 affected package

pypdf

Package 22.04 LTS
pypdf Not in release
Show less packages

CVE-2026-65819

Medium priority

Not in release

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet...

1 affected package

golang-github-gopacket-gopacket

Package 22.04 LTS
golang-github-gopacket-gopacket Not in release
Show less packages

CVE-2026-19113

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory...

1 affected package

consul

Package 22.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-19017

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker...

1 affected package

consul

Package 22.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-19016

Medium priority
Needs evaluation

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network...

1 affected package

consul

Package 22.04 LTS
consul Needs evaluation
Show less packages