Search CVE reports


Toggle filters

21 – 30 of 36507 results

Status is adjusted based on your filters.


CVE-2026-2845

Medium priority

Not in release

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a...

1 affected package

gitlab

Package 22.04 LTS
gitlab Not in release
Show less packages

CVE-2026-27951

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the function `Stream_EnsureCapacity` can create an endless blocking loop. This may affect all client and server implementations...

3 affected packages

freerdp, freerdp2, freerdp3

Package 22.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Not in release
Show less packages

CVE-2026-27950

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution flow referenced in the...

3 affected packages

freerdp, freerdp2, freerdp3

Package 22.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Not in release
Show less packages

CVE-2026-27904

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with...

1 affected package

node-minimatch

Package 22.04 LTS
node-minimatch Needs evaluation
Show less packages

CVE-2026-27903

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive...

1 affected package

node-minimatch

Package 22.04 LTS
node-minimatch Needs evaluation
Show less packages

CVE-2026-27888

Medium priority

Not in release

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader...

1 affected package

pypdf

Package 22.04 LTS
pypdf Not in release
Show less packages

CVE-2026-27837

Medium priority
Needs evaluation

Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The prototype pollution guard introduced in commit `7d3aee1` only validates the first...

1 affected package

node-dottie

Package 22.04 LTS
node-dottie Needs evaluation
Show less packages

CVE-2026-27830

Medium priority
Needs evaluation

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property...

1 affected package

c3p0

Package 22.04 LTS
c3p0 Needs evaluation
Show less packages

CVE-2026-27821

Medium priority
Needs evaluation

GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEnd XML attribute is copied from...

1 affected package

gpac

Package 22.04 LTS
gpac Needs evaluation
Show less packages

CVE-2026-27809

Medium priority

Not in release

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row...

1 affected package

psd-tools

Package 22.04 LTS
psd-tools Not in release
Show less packages