Search CVE reports


Toggle filters

891 – 900 of 45011 results

Status is adjusted based on your filters.


CVE-2026-53583

Medium priority
Needs evaluation

[Unknown description]

1 affected package

libgit2

Package 20.04 LTS
libgit2 Needs evaluation
Show less packages

CVE-2026-68499

Medium priority
Needs evaluation

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching...

1 affected package

node-re2

Package 20.04 LTS
node-re2 Needs evaluation
Show less packages

CVE-2026-55777

Medium priority
Needs evaluation

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the...

1 affected package

goaccess

Package 20.04 LTS
goaccess Needs evaluation
Show less packages

CVE-2026-55768

Medium priority
Needs evaluation

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the...

1 affected package

goaccess

Package 20.04 LTS
goaccess Needs evaluation
Show less packages

CVE-2026-54715

Medium priority
Needs evaluation

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a...

1 affected package

goaccess

Package 20.04 LTS
goaccess Needs evaluation
Show less packages

CVE-2026-67550

Medium priority
Needs evaluation

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace,...

1 affected package

node-re2

Package 20.04 LTS
node-re2 Needs evaluation
Show less packages

CVE-2026-66756

Medium priority
Needs evaluation

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.

1 affected package

tika

Package 20.04 LTS
tika Needs evaluation
Show less packages

CVE-2026-66755

Medium priority
Needs evaluation

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to...

1 affected package

tika

Package 20.04 LTS
tika Needs evaluation
Show less packages

CVE-2026-66066

Medium priority
Needs evaluation

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted...

1 affected package

rails

Package 20.04 LTS
rails Needs evaluation
Show less packages

CVE-2026-59881

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not...

1 affected package

python-aiohttp

Package 20.04 LTS
python-aiohttp Needs evaluation
Show less packages