Search CVE reports


Toggle filters

271 – 280 of 44358 results

Status is adjusted based on your filters.


CVE-2026-16524

Medium priority
Needs evaluation

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

1 affected package

pcp

Package 20.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-64685

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-62946

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-62363

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-62343

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-59898

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version:...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-13346

Medium priority
Needs evaluation

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package...

2 affected packages

pipenv, python-pip

Package 20.04 LTS
pipenv Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-59920

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not escape or validate header values in  CONNECT  and...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-59919

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-59901

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages