Search CVE reports


Toggle filters

271 – 280 of 46143 results

Status is adjusted based on your filters.


CVE-2026-59640

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before...

1 affected package

bouncycastle

Package 22.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-59639

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA)...

1 affected package

bouncycastle

Package 22.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-59638

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA)...

1 affected package

bouncycastle

Package 22.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-18581

Medium priority

Not in release

A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the...

1 affected package

llama.cpp

Package 22.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-15055

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips...

1 affected package

bouncycastle

Package 22.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-12185

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 affected package

bouncycastle

Package 22.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-68580

Medium priority
Needs evaluation

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers....

3 affected packages

freerdp, freerdp2, freerdp3

Package 22.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Not in release
Show less packages

CVE-2026-68579

Medium priority
Needs evaluation

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls...

3 affected packages

freerdp, freerdp2, freerdp3

Package 22.04 LTS
freerdp Not in release
freerdp2 Needs evaluation
freerdp3 Not in release
Show less packages

CVE-2026-9335

Medium priority

Not in release

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the...

1 affected package

keras

Package 22.04 LTS
keras Not in release
Show less packages

CVE-2026-67355

Medium priority

Not in release

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only...

1 affected package

guzzle

Package 22.04 LTS
guzzle Not in release
Show less packages