Search CVE reports


Toggle filters

661 – 670 of 42336 results

Status is adjusted based on your filters.


CVE-2026-66066

Medium priority
Needs evaluation

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted...

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages

CVE-2026-59881

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not...

1 affected package

python-aiohttp

Package 24.04 LTS
python-aiohttp Needs evaluation
Show less packages

CVE-2026-54522

Medium priority
Needs evaluation

MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale...

1 affected package

ruby-msgpack

Package 24.04 LTS
ruby-msgpack Needs evaluation
Show less packages

CVE-2026-51295

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

2 affected packages

sqlite, sqlite3

Package 24.04 LTS
sqlite Not in release
sqlite3 Not affected
Show less packages

CVE-2026-51294

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

2 affected packages

sqlite, sqlite3

Package 24.04 LTS
sqlite Not in release
sqlite3 Not affected
Show less packages

CVE-2026-51293

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

2 affected packages

sqlite, sqlite3

Package 24.04 LTS
sqlite Not in release
sqlite3 Not affected
Show less packages

CVE-2026-51292

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

2 affected packages

sqlite, sqlite3

Package 24.04 LTS
sqlite Not in release
sqlite3 Not affected
Show less packages

CVE-2026-51291

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

2 affected packages

sqlite, sqlite3

Package 24.04 LTS
sqlite Not in release
sqlite3 Not affected
Show less packages

CVE-2026-51290

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

2 affected packages

sqlite, sqlite3

Package 24.04 LTS
sqlite Not in release
sqlite3 Not affected
Show less packages

CVE-2026-13379

Medium priority
Needs evaluation

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

1 affected package

openvpn

Package 24.04 LTS
openvpn Needs evaluation
Show less packages