Search CVE reports


Toggle filters

321 – 330 of 46143 results

Status is adjusted based on your filters.


CVE-2026-18536

Medium priority
Needs evaluation

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The...

1 affected package

libdata-entropy-perl

Package 22.04 LTS
libdata-entropy-perl Needs evaluation
Show less packages

CVE-2026-54909

Medium priority

Not in release

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of...

2 affected packages

golang-github-pion-stun, golang-github-pion-stun-v3

Package 22.04 LTS
golang-github-pion-stun Not in release
golang-github-pion-stun-v3 Not in release
Show less packages

CVE-2026-54787

Medium priority

Not in release

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key...

1 affected package

sigstore-go

Package 22.04 LTS
sigstore-go Not in release
Show less packages

CVE-2026-65981

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against...

1 affected package

coturn

Package 22.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-62959

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and exposes a plaintext-TCP listener, an unauthenticated remote client can send a...

1 affected package

coturn

Package 22.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-53505

Medium priority

Not in release

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger...

1 affected package

thumbor

Package 22.04 LTS
thumbor Not in release
Show less packages

CVE-2026-53504

Medium priority

Not in release

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust...

1 affected package

thumbor

Package 22.04 LTS
thumbor Not in release
Show less packages

CVE-2026-53503

Medium priority

Not in release

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension...

1 affected package

thumbor

Package 22.04 LTS
thumbor Not in release
Show less packages

CVE-2026-53502

Medium priority

Not in release

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through...

1 affected package

thumbor

Package 22.04 LTS
thumbor Not in release
Show less packages

CVE-2026-53501

Medium priority

Not in release

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since...

1 affected package

thumbor

Package 22.04 LTS
thumbor Not in release
Show less packages