Search CVE reports


Toggle filters

761 – 770 of 42041 results

Status is adjusted based on your filters.


CVE-2026-64685

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in...

1 affected package

imagemagick

Package 24.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-62946

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer...

1 affected package

imagemagick

Package 24.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-62363

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has...

1 affected package

imagemagick

Package 24.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-62343

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when...

1 affected package

imagemagick

Package 24.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-15157

Medium priority
Needs evaluation

undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to...

1 affected package

node-undici

Package 24.04 LTS
node-undici Needs evaluation
Show less packages

CVE-2026-14643

Medium priority
Needs evaluation

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the...

1 affected package

node-undici

Package 24.04 LTS
node-undici Needs evaluation
Show less packages

CVE-2026-16728

Medium priority
Needs evaluation

undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 up to...

1 affected package

node-undici

Package 24.04 LTS
node-undici Needs evaluation
Show less packages

CVE-2026-18022

Medium priority
Needs evaluation

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.

1 affected package

pgvector

Package 24.04 LTS
pgvector Needs evaluation
Show less packages

CVE-2026-62995

Medium priority

Not in release

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. in versions 1.7.1 and prior, joserfc accepts JWTs with trailing padding (==) which are not conforming to...

1 affected package

joserfc

Package 24.04 LTS
joserfc Not in release
Show less packages

CVE-2026-59898

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version:...

1 affected package

netty

Package 24.04 LTS
netty Needs evaluation
Show less packages