Search CVE reports


Toggle filters

511 – 520 of 39399 results

Status is adjusted based on your filters.


CVE-2026-77399

Medium priority
Needs evaluation

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can...

1 affected package

python-icalendar

Package 26.04 LTS
python-icalendar Needs evaluation
Show less packages

CVE-2026-83597

Medium priority

Not in release

Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A...

1 affected package

netdata

Package 26.04 LTS
netdata Not in release
Show less packages

CVE-2026-95818

Medium priority
Needs evaluation

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a...

2 affected packages

glibc, eglibc

Package 26.04 LTS
glibc Needs evaluation
eglibc Not in release
Show less packages

CVE-2026-87902

Medium priority
Needs evaluation

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active...

1 affected package

wordpress

Package 26.04 LTS
wordpress Needs evaluation
Show less packages

CVE-2026-83603

Medium priority

Not in release

Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged...

1 affected package

netdata

Package 26.04 LTS
netdata Not in release
Show less packages

CVE-2026-83602

Medium priority

Not in release

Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests...

1 affected package

netdata

Package 26.04 LTS
netdata Not in release
Show less packages

CVE-2026-83601

Medium priority

Not in release

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to pluginsd_rrddim_put_to_slot...

1 affected package

netdata

Package 26.04 LTS
netdata Not in release
Show less packages

CVE-2026-83600

Medium priority

Not in release

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot...

1 affected package

netdata

Package 26.04 LTS
netdata Not in release
Show less packages

CVE-2026-83599

Medium priority

Not in release

Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c...

1 affected package

netdata

Package 26.04 LTS
netdata Not in release
Show less packages

CVE-2026-83598

Medium priority

Not in release

Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and...

1 affected package

netdata

Package 26.04 LTS
netdata Not in release
Show less packages