Search CVE reports


Toggle filters

981 – 990 of 34607 results

Status is adjusted based on your filters.


CVE-2026-14666

Medium priority
Needs evaluation

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan...

7 affected packages

postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...

Package 26.04 LTS
postgresql-18 Needs evaluation
postgresql-16 Not in release
postgresql-14 Not in release
postgresql-12 Not in release
postgresql-10 Not in release
postgresql-9.5 Not in release
postgresql-9.3 Not in release
Show all 7 packages Show less packages

CVE-2026-14664

Medium priority
Needs evaluation

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with...

7 affected packages

postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...

Package 26.04 LTS
postgresql-18 Needs evaluation
postgresql-16 Not in release
postgresql-14 Not in release
postgresql-12 Not in release
postgresql-10 Not in release
postgresql-9.5 Not in release
postgresql-9.3 Not in release
Show all 7 packages Show less packages

CVE-2026-14663

Medium priority
Needs evaluation

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the...

7 affected packages

postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...

Package 26.04 LTS
postgresql-18 Needs evaluation
postgresql-16 Not in release
postgresql-14 Not in release
postgresql-12 Not in release
postgresql-10 Not in release
postgresql-9.5 Not in release
postgresql-9.3 Not in release
Show all 7 packages Show less packages

CVE-2026-14662

Medium priority
Needs evaluation

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute...

7 affected packages

postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...

Package 26.04 LTS
postgresql-18 Needs evaluation
postgresql-16 Not in release
postgresql-14 Not in release
postgresql-12 Not in release
postgresql-10 Not in release
postgresql-9.5 Not in release
postgresql-9.3 Not in release
Show all 7 packages Show less packages

CVE-2026-14456

Medium priority
Needs evaluation

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS
openssl Needs evaluation
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages

CVE-2026-12876

Medium priority
Needs evaluation

[Unknown description]

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-12841

Medium priority
Needs evaluation

[Unknown description]

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2022-4993

Medium priority
Needs evaluation

(HTML::FormHandler versions through 0.40068 for Perl allow attacker sel ...)

1 affected package

libhtml-formhandler-perl

Package 26.04 LTS
libhtml-formhandler-perl Needs evaluation
Show less packages

CVE-2026-9318

Medium priority
Needs evaluation

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which...

1 affected package

python-tablib

Package 26.04 LTS
python-tablib Needs evaluation
Show less packages

CVE-2026-73501

Medium priority
Needs evaluation

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil...

1 affected package

golang-github-getkin-kin-openapi

Package 26.04 LTS
golang-github-getkin-kin-openapi Needs evaluation
Show less packages