Search CVE reports


Toggle filters

351 – 360 of 32959 results

Status is adjusted based on your filters.


CVE-2026-63035

Medium priority
Needs evaluation

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.

1 affected package

open62541

Package 26.04 LTS
open62541 Needs evaluation
Show less packages

CVE-2026-63033

Medium priority
Needs evaluation

A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.

1 affected package

lib60870

Package 26.04 LTS
lib60870 Needs evaluation
Show less packages

CVE-2026-61893

Medium priority
Needs evaluation

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

1 affected package

lib60870

Package 26.04 LTS
lib60870 Needs evaluation
Show less packages

CVE-2026-63559

Medium priority
Needs evaluation

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.

1 affected package

open62541

Package 26.04 LTS
open62541 Needs evaluation
Show less packages

CVE-2026-68499

Medium priority
Needs evaluation

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching...

1 affected package

node-re2

Package 26.04 LTS
node-re2 Needs evaluation
Show less packages

CVE-2026-55777

Medium priority
Needs evaluation

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the...

1 affected package

goaccess

Package 26.04 LTS
goaccess Needs evaluation
Show less packages

CVE-2026-55768

Medium priority
Needs evaluation

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the...

1 affected package

goaccess

Package 26.04 LTS
goaccess Needs evaluation
Show less packages

CVE-2026-54715

Medium priority
Needs evaluation

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a...

1 affected package

goaccess

Package 26.04 LTS
goaccess Needs evaluation
Show less packages

CVE-2026-67550

Medium priority
Needs evaluation

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace,...

1 affected package

node-re2

Package 26.04 LTS
node-re2 Needs evaluation
Show less packages

CVE-2026-66756

Medium priority
Needs evaluation

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.

1 affected package

tika

Package 26.04 LTS
tika Needs evaluation
Show less packages