Search CVE reports


Toggle filters

1 – 10 of 32445 results

Status is adjusted based on your filters.


CVE-2026-27446

Medium priority
Needs evaluation

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core...

1 affected package

activemq

Package 24.04 LTS
activemq Needs evaluation
Show less packages

CVE-2025-66168

Medium priority
Needs evaluation

Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining...

1 affected package

activemq

Package 24.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-27932

Medium priority

Not in release

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to...

1 affected package

joserfc

Package 24.04 LTS
joserfc Not in release
Show less packages

CVE-2026-27622

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated...

1 affected package

openexr

Package 24.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-27601

Medium priority
Needs evaluation

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in...

1 affected package

ruby-rails-assets-underscore

Package 24.04 LTS
ruby-rails-assets-underscore Needs evaluation
Show less packages

CVE-2026-29022

Medium priority
Needs evaluation

dr_libs version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV...

5 affected packages

dosbox-x, faudio, octave-ltfat, qtads, roc-toolkit

Package 24.04 LTS
dosbox-x Needs evaluation
faudio Needs evaluation
octave-ltfat Needs evaluation
qtads Needs evaluation
roc-toolkit Needs evaluation
Show less packages

CVE-2026-0540

Medium priority
Needs evaluation

DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2025-15599

Medium priority
Needs evaluation

DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the...

1 affected package

node-dompurify

Package 24.04 LTS
node-dompurify Needs evaluation
Show less packages

CVE-2026-22891

Medium priority
Needs evaluation

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution....

1 affected package

biosig

Package 24.04 LTS
biosig Needs evaluation
Show less packages

CVE-2026-20777

Medium priority
Needs evaluation

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An...

1 affected package

biosig

Package 24.04 LTS
biosig Needs evaluation
Show less packages